Re: UDP Port Sweep question

From: Tim (tim-forensics_at_sentinelchicken.org)
Date: 12/29/04

  • Next message: Kyle Maxwell: "Re: UDP Port Sweep question"
    Date: Tue, 28 Dec 2004 18:52:35 -0500
    To: Billy Dodson <CraftedPacket@securitynerds.org>
    
    

    > I monitor 3 different sensors which are continuously pounded with network
    > reconnaissance of all types.

    I assume these are outside of firewalls?

    > These sensors all belong to financial
    > institutions. One thing that jumped out at me are "UDP Port Sweeps"
    > events from about 15 different IP addresses which all belong to either IBM
    > or Sequent (which was bought by IBM). I see these same IP addresses doing
    > the same thing on all three sensors. I have contacted the clients and
    > they do not deal with IBM or Sequent in any way. Are there legitimate type
    > traffic
    > that would cause these events to fire?

    Can you provide more information? Source and destination ports, ttls,
    etc? Otherwise I wouldn't know how to answer such a question.

    > It is odd to me that I see them on
    > all 3 sensors for 3 different companies but all happen to be in the
    > financial industry. Thanks in advance for your input.

    It wouldn't be the first time that the financial industry was targetted.
    Then again, it could be nothing.

    tim


  • Next message: Kyle Maxwell: "Re: UDP Port Sweep question"

    Relevant Pages

    • Re: UDP Port Sweep question
      ... Might I suggest you post some of the packets here? ... >events from about 15 different IP addresses which all belong to either IBM ... >they do not deal with IBM or Sequent in any way. ... >financial industry. ...
      (Incidents)
    • UDP Port Sweep question
      ... I monitor 3 different sensors which are continuously pounded with network ... events from about 15 different IP addresses which all belong to either IBM ... they do not deal with IBM or Sequent in any way. ...
      (Incidents)
    • Hardware sensors problem with 2.4.21 on IBM eServer 335/345
      ... voltage sensors) working on an IBM eServer 335 system that is running ... RedHat with kernel 2.4.21. ... The driver for the sensors chip on this particular mainboard is found ...
      (Linux-Kernel)
    • Re: How to find which chips have RFID?
      ... RFID sensors track the shipments and associates them with the carrier vehicle. ... that combination of technology is what is represented in the IBM ... > would be able to differentiate chips among many players. ...
      (rec.gambling.craps)
    • [PATCH] v1 of IBM power meter driver
      ... fashion similar to temperature/rpm/current sensors. ... ibm_pex: Driver to export IBM PowerExecutive power meter sensors. ... * GNU General Public License for more details. ...
      (Linux-Kernel)

  • Quantcast