scans on port 57
From: Ingersoll, Jared (jared@cswv.com)Date: 11/12/02
- Previous message: Steenbergen, Dennis, Contractor: "RE: Ip spoof from 0.0.0.0"
- Next in thread: John Jørgensen: "Re: scans on port 57"
- Reply: John Jørgensen: "Re: scans on port 57"
- Reply: Craig, Scott: "RE: scans on port 57"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Ingersoll, Jared" <jared@cswv.com> To: incidents@securityfocus.com Date: Tue, 12 Nov 2002 08:00:39 -0500
I'm seeing a lot of blocked scans on port 57 in my firewall logs, many times
in conjunction with a port 80 or port 21 scan. I was working under the
assumption that these were related to a misconfigured port scanner, but I'm
seeing them from a pretty diverse set of source addresses, so now I'm
curious what they're looking for.
jared
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
- Previous message: Steenbergen, Dennis, Contractor: "RE: Ip spoof from 0.0.0.0"
- Next in thread: John Jørgensen: "Re: scans on port 57"
- Reply: John Jørgensen: "Re: scans on port 57"
- Reply: Craig, Scott: "RE: scans on port 57"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|