Re: Large increase in port 32772 activity

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 12/29/03

  • Next message: J Bailes: "RE: Unusual port scan?"
    Date: Mon, 29 Dec 2003 14:00:38 -0500
    To: Christopher Harrington <cmh@nmi.net>, Incidents <incidents@securityfocus.com>
    
    

    Christopher Harrington wrote:

    > All,
    >
    > Several of our customers are seeing very significant increase in port
    > 32772 activity. They are single packets of which I do not have the size.
    > One customer had over 1500 different hosts sending a single packet to
    > 32772 in a 6 hour period. The vast majority of those hosts were probably
    > zombies since they were Verizon DSL, Comcast, AT&T ip addresses. I know
    > spammers look for 32772 to be open because Checkpoint can use this port
    > for SMTP.

    Ports 32770-32789 are technically "RPC Loopback" ports. Quoting from
    the SANS recommendations "Block the RPC portmapper, port 111 (TCP and
    UDP) and Windows RPC, port 135 (TCP and UDP), at the border router or
    firewall. Block the RPC "loopback" ports, 32770-32789 (TCP and UDP).
    See http://www.sans.org/top20/.

    However, I have found that many default versions of BIND will also use
    these as ephemeral ports when querying another name server. For this
    purpose we allow 32770-32789 -> 53.

    Jeff

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: J Bailes: "RE: Unusual port scan?"

    Relevant Pages

    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... Look in IIS at your Exchweb, Exadmin, exchange-oma, and RPC sites' directory ... Why is it called RPC over HTTP if HTTP is not really needed to be ... As pointed out by others, port 80 does NOT need to be open, and yes, it ... I have about 20 of these SBS machines at other locations and have ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... , but some of my clients do not want users to ... definitely closed now cause when I open it up http: ... the article is incorrect in stating that port 80 is needed. ... that port 443 and port 80 must be open to use RPC over HTTP. ...
      (microsoft.public.windows.server.sbs)
    • Re: Intersite Replication problem
      ... I followed Antony's DNS advise and I seens to be working. ... To perform the replication I've schedule a task on the W3K server to dial ... As for RPC The default value for the RPC Replication Timeout registry ... Remote Procedure Call dynamic port allocation is used by remote ...
      (microsoft.public.windows.server.active_directory)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... definitely closed now cause when I open it up http: ... the article is incorrect in stating that port 80 is needed. ... that port 443 and port 80 must be open to use RPC over HTTP. ... I have about 20 of these SBS machines at other locations and have ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... Look in IIS at your Exchweb, Exadmin, exchange-oma, and RPC sites' directory ... manually...I just let the CEICW do it for me. ... Why is it called RPC over HTTP if HTTP is not really needed to be ... As pointed out by others, port 80 does NOT need to be open, and yes, it ...
      (microsoft.public.windows.server.sbs)