Logs: Many hits with source port of 80

From: Byrne Ghavalas (security@nscs.uk.com)
Date: 12/13/02

  • Next message: Romulo M. Cholewa: "Terminal Services / TsInternetUser [RMC-RUFLVP4]"
    From: "Byrne Ghavalas" <security@nscs.uk.com>
    To: <incidents@securityfocus.com>
    Date: Fri, 13 Dec 2002 10:05:56 -0000
    
    

    Hi All,

    Has anyone else noticed a high number of hits in their security logs,
    where the source port is set to tcp 80 and the destination port is some
    high tcp port? I have noticed that these events seem to be getting more
    numerous than the NetBios scans ;-)

    For example:
    2002-12-13 09:08:04 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:07:04 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:06:05 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:05:04 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:04:04 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:03:05 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:02:04 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:01:28 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:01:10 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:01:01 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:00:57 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:00:55 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:00:54 194.78.225.36:80 XX.XX.XX.XX:29439
    2002-12-13 09:00:54 194.78.225.36:80 XX.XX.XX.XX:29439

    It appears to be some kind of automated scan as the time of each entry
    appears to follow a pattern.

    Byrne Ghavalas

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: excessive TCP dulplicate acks revisted
      ... The tcp duplicate ACK attack is back. ... there was a thread on duplicate TCP acks in -CURRENT. ... TCP STREAM TEST from localhost port 0 AF_INET to greenhouse- george.18clay.com port 0 AF_INET ... Socket Socket Message Elapsed ...
      (freebsd-current)
    • excessive TCP dulplicate acks revisted
      ... The tcp duplicate ACK attack is back. ... there was a thread on duplicate TCP acks in -CURRENT. ... TCP STREAM TEST from localhost port 0 AF_INET to greenhouse- george.18clay.com port 0 AF_INET ... Socket Socket Message Elapsed ...
      (freebsd-current)
    • Re: How to tell if a firewall alert is suspicious or not
      ... > WHY this SBCGlobal DNS server would be contacting Adobe Acrobat on port ... They have to parts, a kernel and the userland, in which programs, which are ... With Internet Protocol and TCP it is so, that any network interface in the ... To initiate a TCP connection, first the server has to "listen" on a port. ...
      (comp.security.firewalls)
    • RE: Configure Hardware Firewall for SBS 2003
      ... the corresponding ports to the SBS box. ... When a router is deployed at the SBS end, you must forward the port numbers ... TCP 110 This port is used for POP3 mail clients. ... TCP 1723 PPTP VPN connection ...
      (microsoft.public.windows.server.sbs)
    • Ports and Protocols
      ... A TCP or UDP connection is defined by the 4-tuple (source IP, ... port, destination IP, destination port). ... destination port) combination. ... pairs are separate for TCP and UDP stacks. ...
      (alt.computer.security)