Re: UDP Port Sweep question

From: Ron (iago_at_valhallalegends.com)
Date: 12/29/04

  • Next message: Billy Dodson: "RE: UDP Port Sweep question"
    Date: Wed, 29 Dec 2004 11:05:28 -0600
    To: CraftedPacket@securitynerds.org
    
    

    I often see UDP_PORT_SWEEP hits from virus scan servers. Virus scanners
    will look for their clients on a udp port, and trigger the signature.
    We just set up a rule to ignore antivirus boxes' udp probes.

    Of course, it may also be something totally different, but that's one
    thing that could cause it.

    Billy Dodson wrote:

    >I monitor 3 different sensors which are continuously pounded with network
    >reconnaissance of all types. These sensors all belong to financial
    >institutions. One thing that jumped out at me are "UDP Port Sweeps"
    >events from about 15 different IP addresses which all belong to either IBM
    >or Sequent (which was bought by IBM). I see these same IP addresses doing
    >the same thing on all three sensors. I have contacted the clients and
    >they do not deal with IBM or Sequent in any way. Are there legitimate type
    >traffic
    >that would cause these events to fire? It is odd to me that I see them on
    >all 3 sensors for 3 different companies but all happen to be in the
    >financial industry. Thanks in advance for your input.
    >
    >
    >
    >


  • Next message: Billy Dodson: "RE: UDP Port Sweep question"

    Relevant Pages

    • Re: Windows 2003 Server NAT not allowing IPSEC to go through.
      ... connect to their server using IPSec. ... NIC and in NAT, no packet filtering on the NIC or in NAT... ... > The clients are using Nortal Extranet that connects through IPSec (their ... documentation asks that IP Port 50, UDP Port 500 and UDP Port 2001 be ...
      (microsoft.public.win2000.ras_routing)
    • Re: Blocking UDP Port 1434
      ... We are talking about thousands of clients and I am not ... sure all applications support the use of aliases. ... >> planning to block UDP Port 1434 on all gateways. ...
      (microsoft.public.sqlserver.server)
    • Re: How port forwarding programs really work?
      ... clients, but we don't. ... as the server uses just one UDP port for the ... header which comes before the IP header) could be used to distinguish ... manipulate the ethernet header using the raw sockets and that means ...
      (microsoft.public.win32.programmer.networks)