Re: Packet from port 80 with spoofed microsoft.com ip

From: dr john halewood (john@frumious.unidec.co.uk)
Date: 01/30/03

  • Next message: Michael Rowe: "Re: Packet from port 80 with spoofed microsoft.com ip"
    From: dr john halewood <john@frumious.unidec.co.uk>
    To: incidents@securityfocus.com
    Date: Thu, 30 Jan 2003 18:10:29 +0000
    
    

    On Thursday 30 January 2003 03:31, Keith Owens wrote:
    >I am seeing a lot of sync/ack packets from port 80 to non-existent
    >addresses on my networks. Somebody is spoofing source addresses to
    >attack hosts, we are just innocent victims. When will ISPs learn that
    >they should filter their customer's packets to prevent spoofing? I am
    >even seeing syn/ack packets from 255.255.255.255:80!

    Ditto, started getting these earlier on today (and also others from there
    going to 1080 and 3128). They definitely _aren't_ backscatter but I'm equally
    amazed that they get through. Interestingly snort fingered some of the port
    80 probes as possible Backdoor Q accesses.

    cheers
    john

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: What is going on with my Dialup?
      ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
      (comp.os.linux.networking)
    • Re: OT .. Road Warrior communications question
      ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
      (alt.guitar.bass)
    • RE: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)
      ... It seems to me that packets with that destination address ... of nearby networks -- probably only the local network itself. ... Look at the source MAC addresses. ... UDP port 80.... ...
      (Incidents)
    • Re: Logs: Many hits with source port of 80
      ... The hits from source port 80 to dest port 37852 are IMHO almost ... you should probably see a couple other packets - perhaps ... packets if either you send the load balancer a packet, ... >>I have seen similar hits for the past three months. ...
      (Incidents)
    • Re: Error 720 connecting to server via VPN
      ... By default the router's firewall is configured to drop ICMP packets ... Select WAN Setup> Advanced> Respond to Ping on Internet Port. ... server and the Internet allow GRE packets. ... routers on the user's network are also configured to allow GRE packets. ...
      (microsoft.public.windows.server.sbs)