RE: UDP Port Sweep question

From: David Gillett (gillettdavid_at_fhda.edu)
Date: 12/29/04

  • Next message: Tim: "Re: UDP Port Sweep question"
    To: "'Billy Dodson'" <billy@pmm-i.com>, <dparker@bridonsecurity.com>
    Date: Wed, 29 Dec 2004 11:11:08 -0800
    
    
    

      These port numbers are all in the range used by UDP-based versions
    of traceroute....

    > -----Original Message-----
    > From: Billy Dodson [mailto:billy@pmm-i.com]
    > Sent: Wednesday, December 29, 2004 10:35 AM
    > To: dparker@bridonsecurity.com
    > Cc: incidents@securityfocus.com
    > Subject: RE: UDP Port Sweep question
    >
    >
    > Here is some more info regarding the port sweeps. The port the client
    > is being hit on seems to vary. The client is being hit on the same 8
    > port range from each IP port 33434-33460. All 3 sensors from the 3
    > different clients show the same destination port range. The
    > sensors are
    > cisco IDS sensors and I am unsure as to how to get the actual packet
    > from the event.
    >
    >
    > -----Original Message-----
    > From: Don Parker [mailto:dparker@bridonsecurity.com]
    > Sent: Tuesday, December 28, 2004 5:12 PM
    > To: incidents@securityfocus.com; 'Billy Dodson'
    > Subject: Re: UDP Port Sweep question
    >
    > Hello Billy,
    >
    > Might I suggest you post some of the packets here? It is hard to make
    > judgement
    > calls without something to look at. Just sanitize the ip's prior to
    > posting the
    > packets.
    >
    > Cheers,
    >
    > Don
    >
    > --------------------------------------------------------------
    > Don Parker, GCIA GCIH
    > Intrusion Detection & Incident Handling Specialist
    > Bridon Security & Training Services
    > http://www.bridonsecurity.com
    > voice: 1-613-302-2910
    > --------------------------------------------------------------
    >
    > On Tue, 28 Dec 2004 22:31 , 'Billy Dodson'
    > <CraftedPacket@securitynerds.org> sent:
    >
    > >I monitor 3 different sensors which are continuously pounded with
    > network
    > >reconnaissance of all types. These sensors all belong to financial
    > >institutions. One thing that jumped out at me are "UDP Port Sweeps"
    > >events from about 15 different IP addresses which all belong
    > to either
    > IBM
    > >or Sequent (which was bought by IBM). I see these same IP addresses
    > doing
    > >the same thing on all three sensors. I have contacted the
    > clients and
    > >they do not deal with IBM or Sequent in any way. Are there legitimate
    > type
    > >traffic
    > >that would cause these events to fire? It is odd to me that
    > I see them
    > on
    > >all 3 sensors for 3 different companies but all happen to be in the
    > >financial industry. Thanks in advance for your input.
    >
    >
    >
    >
    >
    >

    
    



  • Next message: Tim: "Re: UDP Port Sweep question"

    Relevant Pages

    • Re: How port forwarding programs really work?
      ... So for each client you will can map a dedicated source port on the PF server that is used to handle the request/response between the PF and S for the specific client. ... - there's a computer 'S' on which some game server (or any server like ... like 1234 and waits for UDP packets. ...
      (microsoft.public.win32.programmer.networks)
    • How port forwarding programs really work?
      ... I'm trying to code a port forwarding program using raw sockets. ... like 1234 and waits for UDP packets. ... packet is coming directly from a client, ...
      (microsoft.public.win32.programmer.networks)
    • Re: Question about sockets/listeners
      ... a script that simulates lots of clients sending UDP packets to the ... These clients should send a UDP packet from a particular port ... trying to run each simulated client in a different thread. ...
      (comp.lang.ruby)
    • Re: Setting up a Windows VPN through a Fedora Linux gateway
      ... >>port redirection, ... The windows vpn is a client, ... > need for port forwarding at the client end. ... Then you can see what packets are going ...
      (comp.os.linux.networking)
    • Re: UDP on Windows 7/ Vista
      ... listens on some port for commands, one of the commands is to give updates to ... the client at a given rate to a given port. ... Vista too), we ran into the problem if the client is on the local host, it ... You can't sniff the localhost packets with wireshark. ...
      (microsoft.public.win32.programmer.networks)