Re: Scanning Port UDP 4668

From: H C (keydet89@yahoo.com)
Date: 07/22/02


Date: Mon, 22 Jul 2002 10:29:51 -0700 (PDT)
From: H C <keydet89@yahoo.com>
To: Ken Grossman <kgrossman@dazzling.com>, incidents@securityfocus.com

Ken,

I'm really kind of suprised that a CISSP is taking
this approach to such a problem.

Okay...this group has identified a number of UDP
packets headed for this port. Fine. *How* did they
find them? Were they dropped by a firewall? If
so...so what? Better to spend the time on things that
matter than chasing after shiny objects.

Were they logged by an IDS? If so, what data is
carried in the datagram?

Assuming that no egress filtering is being done by
this group, maybe what they can do is identify the
systems using the destination IPs of the datagrams,
then go to those boxes and run fport.exe (NT/2K) or
'netstat -ano' (XP) or lsof (Linux) to see if anything
*is*, in fact, listening on that port.

--- Ken Grossman <kgrossman@dazzling.com> wrote:
> All,
>
> One of the groups that I support has been seeing a
> lot of scanning for UDP
> port 4668. Before you ask, they did not quantify "a
> lot". One of the
> questions that they have is what are the scanners
> looking for that is
> running on that port. I checked the IANA port
> listing at
> www.iana.org/assignments/port-numbers and found that
> the port number (TCP
> and UDP) is unassigned. I also performed a check on
> the SecurityFocus site
> to see if this had bee discussed before but found
> nothing on it. Does
> anyone know what could be running on that port
> number? Thanks for your
> assistance.
>
>
> Ken Grossman, CISSP
> kgrossman@dazzling.com
> (202) 401-7142
>
>
>
----------------------------------------------------------------------------
> This list is provided by the SecurityFocus ARIS
> analyzer service.
> For more information on this free incident handling,
> management
> and tracking system please see:
> http://aris.securityfocus.com
>

__________________________________________________
Do You Yahoo!?
Yahoo! Health - Feel better, live better
http://health.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Block UDP Ports?
    ... I'm using Checkpoint Firewall-1. ... reasonable that Firewall-1 would leave UDP wide open. ... > UDP ICMP port unreachable scanning: This scanning method varies from the ...
    (comp.security.firewalls)
  • UDP DoS attack in Win2k via IKE
    ... This memo should clarify the issue discovered with the UDP DOS ... Sending of UDP traffic to port 500 UDP will cause windows to ... attacked host is an IPSec gateway). ...
    (Bugtraq)
  • Re: LDAP UDP Port Problem
    ... The correct fix is to identify that the network gear is tossing out the UDP ... Then I did some portqry's on the LDAP port ... > Sending LDAP query to TCP port 389... ...
    (microsoft.public.windows.server.networking)
  • Re: Block UDP Ports?
    ... UDP scanning is questionable to many - if the port is open, ... closed ports aren't even required to send an error packet. ...
    (comp.security.firewalls)
  • Re: LDAP UDP Port Problem
    ... The correct fix is to identify that the network gear is tossing out the UDP ... Then I did some portqry's on the LDAP port ... > Sending LDAP query to TCP port 389... ...
    (microsoft.public.windows.server.setup)