RE: Port 1080

From: Krueger Lawrence (Lawrence.Krueger@kohler.com)
Date: 11/22/02

  • Next message: Esler, Joel -- Sytex Contractor: "RE: increased attacks on port 2599"
    From: Krueger Lawrence <Lawrence.Krueger@kohler.com>
    To: "'Chris Gross'" <chris@hugehosting.com>
    Date: Fri, 22 Nov 2002 08:39:01 -0600
    
    

    Port 1080 is a socks proxy server and the attacker was using this server as
    a middle man in this attack to protect his true ip.

    LK

    -----Original Message-----
    From: Chris Gross [mailto:chris@hugehosting.com]
    Sent: Wednesday, November 20, 2002 4:57 PM
    To: Incidents Mailing List
    Subject: Port 1080

    We had a large spike in connections through our firewall and we tracked it
    down to a Linux 8.0 server. It was creating about 200K connections with a
    source and destination port of 1080. Has anyone else seen this.

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: Appeal for Help. NOT Code Red But Is It?
      ... our server immediately responds back to the prober ... What is happening is that the IDS is becomming confused about who the ... each worm that is still on its way from the attacker. ... > and outbound port was 2913. ...
      (Incidents)
    • Re: Question: FTP via alternate port
      ... detection techniques based on port. ... regarding your SQL server on the internal net; ... Why would you want to open your SQL server to the outside world? ... Theoretically an attacker could still compromise your SQL by hitting the ...
      (Pen-Test)
    • TCP 6129 - Dameware, TCP 17890 IIS.EXE, SVR1984.exe - Team Liquid
      ... Win2K advanced server, and during analysis I found that the DameWare remote ... service and listens on TCP port 6129 by default. ... have allowed the attacker to execute any command line could have been used. ... NAI says this about the RQ trojan: ...
      (Incidents)
    • Re: Trojan? DDOS Bot?
      ... >internet a connection from local port 1026 to port 6667 ... >server and it is an irc server (MusIRC Internet Relay ... >LISTENING ... >and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)
    • Re: all port scan attack notifications
      ... going to use something as simple and noisy as a regular port scan. ... IP will be rotated so you don't know it's the same attacker. ... detection time when that happens. ... investigation turn out to be from a companies mail server. ...
      (microsoft.public.isa)