Scan of TCP 552-554

From: Bill McCarty (bmccarty_at_pt-net.net)
Date: 07/24/03

  • Next message: Russell Fulton: "Re: Port 0 packets"
    Date: Thu, 24 Jul 2003 00:08:21 -0700
    To: Incidents <incidents@securityfocus.com>
    
    

    Hi all,

    A scan of TCP 552-554 just passed through my class C network. The scanner
    expressed some interest in one host listening on TCP 554 and so is pretty
    clearly looking for RTSP servers. As it happens, the responding server is a
    honeypot running Windows 2003. The scanner didn't seem to send an attack;
    apparently, it was merely a probe.

    What might it be looking for on TCP 552-553 and, more particularly, why
    might a scanner interested in RTSP also scan those ports? The ports are
    registered for use by deviceshare and PIRP (Public Information Retrieval
    Protocol). But, I don't suspect that the scanner is interested in those
    services, since they don't seem to be associated with RTSP. Could the
    scanner simply be comparing the response for port 554 with those for the
    other ports, in order to assess possible firewall rules?

    Thanks for your thoughts!

    ---------------------------------------------------
    Bill McCarty

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Russell Fulton: "Re: Port 0 packets"

    Relevant Pages

    • Problems with libpcap on 4.9-STABLE
      ... After a little investigation I found that the problem is the way libpcap ... changing the default yy prefix, then the generated scanner will conflict ... with the scanner generated by /usr/src/contrib/libpcap/scanner.l. ... # ./test_pcap 'tcp and udp' ...
      (freebsd-hackers)
    • Problems with libpcap on 4.9-STABLE
      ... After a little investigation I found that the problem is the way libpcap ... changing the default yy prefix, then the generated scanner will conflict ... with the scanner generated by /usr/src/contrib/libpcap/scanner.l. ... # ./test_pcap 'tcp and udp' ...
      (freebsd-stable)
    • Re: Event 4226 issue - TCP half open connection limits.
      ... writing your scanner under Linux... ... Microsoft MVP, MCSD ... > open TCP connections. ... > show network timeout. ...
      (microsoft.public.win32.programmer.networks)
    • Re: Iptables udp problems
      ... >> another computer on my local network, scanner shows all udp ports ... With my second INPUT -p tcp i deny remaining rst packets. ...
      (comp.security.firewalls)
    • Re: Scan of TCP 552-554
      ... > might a scanner interested in RTSP also scan those ports? ... I don't suspect that the scanner is interested in those ... if you do a TCP scan from port 135 to port 140 on a Windows ... range, but left the system otherwise unprotected, with Windows sending a ...
      (Incidents)