Re: Surge of attacks on ports 61127 & 61134

From: Joseph (joseph@netSecureLabs.CA)
Date: 07/26/02


Date: Thu, 25 Jul 2002 18:05:33 -0400 (EDT)
From: Joseph <joseph@netSecureLabs.CA>
To: H C <keydet89@yahoo.com>


Good point. No, I can't say its an attack. You are correct, in that I
assume an attack. Normally every morning, I simply review my log(s),
tripwire, snort, and so forth. This morning these 2 ports poped up.

I recongized originating domains from top-10 attack lists, so I assumed.

I'll setup a packet capture, and feedback with my findings. I think snort
can do this?

Someone mentioned using Linux as a masquading firewall system, causing
such a thing. I'll look into that, I find it odd, as I've not noticed this
behavier ever.

All my sources are from "dialups" IPs, that's what I find odd, with a
higher presence from outside north-america addresses. So in my mind, I
ruled out standard traffic.

sorry about the panic. let me get more info.

On Thu, 25 Jul 2002, H C wrote:
> Joseph,
>
> How do you know that these are attacks? Did you
> capture the contents of the datagrams? Have you found
> anything listening on those ports on the destination
> IPs?
>
>
> --- Joseph <joseph@netSecureLabs.CA> wrote:
> >
> > This morning my logs showed me a surge of new UDP
> > packets attacks, mainly
> > to ports 61127 & 61134 . I can't find any info on
> > this, so I'm wondering
> > what it can be.
> >
> > It seems very well known, if I can say, because
> > source IPs are from
> > everywhere, I must have gotten a good 50-80 probes.
> >
> > I see alot different *dip.t-dialin.net orgin
> > sources, which
> > *dip.t-dialin.net seems to make the top 10 attack
> > list at dshield and
> > incidents' website.
> >
> > Curious, new virus? or attack tool?
> >
> > I don't have a log of the packet, justs its denial
> > attempt. Normally, all
> > my attacks are standard stuff, this pops out like
> > really new...
> >
> >
> >
> >
> >
> ----------------------------------------------------------------------------
> > This list is provided by the SecurityFocus ARIS
> > analyzer service.
> > For more information on this free incident handling,
> > management
> > and tracking system please see:
> > http://aris.securityfocus.com
> >
>
>
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Health - Feel better, live better
> http://health.yahoo.com
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Developmental Dictionary Attack
    ... Do you have any idea where people get their lists of common ... use your data gathering method as an input to a real world attack. ... high security systems can have physical lockouts, ... word dictionaries aren't too unusual for this) and then you iterate ...
    (sci.crypt)
  • Re: Why misc.survivalism should keep on talking about _THREAT MODELS_
    ... threat models and how to deal with them. ... big attack - the one we won't recover from. ... participants to do a smallpox vaccine study, ... you have done the same with your "lists". ...
    (misc.survivalism)
  • Re: Agendas
    ... and uses falses identities like ianhillsmith to attack ... copies stuff from all over for your postings. ... One who sets up blogs and mails to lists about how evil and horrible ... exist as long as yahoo groups and usenet groups have online archives, ...
    (sci.astro.amateur)
  • Re: Publishing Nimda Logs == BAD IDEA
    ... >we will NOT, however, be publishing a comprehensive list of infected ... these worm infection attempts ... by the fact that the sources for such an attack would have already been ... if you have your own lists of infected hosts, ...
    (Vuln-Dev)
  • Dear SCI Friends
    ... with IRI and it *is* related to IRI ... had 2000 emails in the DS attack. ... I sent Mr. Siamak Farahbakhshian the ... to keep such lists as obedient to ...
    (soc.culture.iranian)