Re: Logs: Many hits with source port of 80

From: Valdis.Kletnieks@vt.edu
Date: 12/16/02

  • Next message: Maxime Ducharme: "Re: Many hits with source port of 80"
    To: Byrne Ghavalas <security@nscs.uk.com>
    From: Valdis.Kletnieks@vt.edu
    Date: Mon, 16 Dec 2002 11:01:45 -0500
    

    On Fri, 13 Dec 2002 10:05:56 GMT, Byrne Ghavalas <security@nscs.uk.com> said:
    > Has anyone else noticed a high number of hits in their security logs,
    > where the source port is set to tcp 80 and the destination port is some
    > high tcp port? I have noticed that these events seem to be getting more
    > numerous than the NetBios scans ;-)
    >
    > For example:
    > 2002-12-13 09:08:04 194.78.225.36:80 XX.XX.XX.XX:29439

    The analysis differs considerably depending on whether these were SYN packets,
    or SYN+ACK. If they're SYN packets *from* 80, that's odd in one way - however a
    SYN+ACK would probably indicate either backscatter from a DDoS where somebody
    used your IP as a forged source address, or that you were having a nice burn of
    some worm on your internal net, and they were all trying to phone home..

    -- 
    				Valdis Kletnieks
    				Computer Systems Senior Engineer
    				Virginia Tech
    
    




    Relevant Pages

    • Duane is a very cewl guy, dont insult him!!!
      ... because I've got a service running on that port. ... In the firewall logging I see that NIS is blocking TCP SYN ... > So does anyone know how to tell NIS2003 to let these SYN packets through? ...
      (comp.security.firewalls)
    • NIS2003 blocks TCP SYN packets on port 4662
      ... I've set up Norton Internet Security 2003 to allow any traffic on TCP port ... In the firewall logging I see that NIS is blocking TCP SYN ... So does anyone know how to tell NIS2003 to let these SYN packets through? ...
      (comp.security.firewalls)
    • Re: finding # of free outgoing TCP port in Sol 8
      ... > port numbers. ... > The source port number. ... > The destination port number. ... the number of ports was not increased for TCP over IPv6. ...
      (comp.unix.solaris)
    • Re: finding # of free outgoing TCP port in Sol 8
      ... >> The source port number. ... Yeah, so it's a protocol restriction, because TCP uses 16-bit unsigned ... but I was too lazy ...
      (comp.unix.solaris)
    • Re: excessive TCP dulplicate acks revisted
      ... The tcp duplicate ACK attack is back. ... there was a thread on duplicate TCP acks in -CURRENT. ... TCP STREAM TEST from localhost port 0 AF_INET to greenhouse- george.18clay.com port 0 AF_INET ... Socket Socket Message Elapsed ...
      (freebsd-current)