Odd MS-Sql scans.

From: larosa, vjay (larosa_vjay_at_emc.com)
Date: 10/20/03

  • Next message: Michael Scheidell: "Re: Odd MS-SQL scan."
    To: "'incidents@securityfocus.com'" <incidents@securityfocus.com>
    Date: Mon, 20 Oct 2003 10:56:34 -0400
    
    

    Hello,

    This morning while reviewing my IDS logs I found about 1,000 events all
    originating from one source IP (64.166.152.138) incrementally scanning one
    of my subnets for port 1433. These scans were odd to me because the packet
    payload was cko (Q traffic payload) the flags were AR, Sequence number,
    Acknowledgment number, and TCP window size numbers were all 0, and the TTL
    is always between 1-2 (this might be because the stream4 TTL evasion flagged
    these packets). Is anybody else seeing anything like this?

    Thanks!
     
    vjl

    V.Jay LaRosa EMC Corporation
    Information Security 4400 Computer Dr.
    (508)898-7433 Office Westboro, MA 01580
    (508)962-1482 Cell www.emc.com
    888-799-9750 Pager vjl@emc.com

    ---------------------------------------------------------------------------
    FREE Whitepaper: Better Management for Network Security

    Looking for a better way to manage your IP security?
    Learn how Solsoft can help you:
    - Ensure robust IP security through policy-based management
    - Make firewall, VPN, and NAT rules interoperable across heterogeneous
    networks
    - Quickly respond to network events from a central console

    Download our FREE whitepaper at:
    http://www.securityfocus.com/sponsor/Solsoft_incidents_031015
    ----------------------------------------------------------------------------


  • Next message: Michael Scheidell: "Re: Odd MS-SQL scan."

    Relevant Pages

    • RE: Auditing enabled but Logon Failures not showing up
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • RE: Auditing enabled but Logon Failures not showing up
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • Re: Terminal Services Auditing?
      ... Read Special Ops and mount an assault to eradicate network negligence today. ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • RE: Alternatives to sftp?
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Security-Basics)
    • RE: Alternatives to sftp?
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Security-Basics)