RE: Increase seen in port probes since Tuesday afternoon

From: M. Shirk (shirkdog_list_at_hotmail.com)
Date: 12/30/04

  • Next message: James C Slora Jr: "RE: Increase seen in port probes since Tuesday afternoon"
    To: incidents@securityfocus.com
    Date: Thu, 30 Dec 2004 14:23:02 -0500
    
    

    Its one of the *bot variants It is looking for other infected machines on
    those ports and other services to compromise. I get the same in my firewall
    and ids logs.

    http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=37776

    Shirkdog
    http://www.shirkdog.us

    >From: BahdKo <bahdko@erols.com>
    >To: incidents@securityfocus.com
    >Subject: Increase seen in port probes since Tuesday afternoon
    >Date: Thu, 30 Dec 2004 11:22:51 +0200
    >
    >Is anyone else seeing this?
    >
    >Since Tuesday afternoon EST I've seen a dramatic increase in the number of
    >machines probing my network on ports 2745, 1025, 3127, 6129, and usually
    >80. Each probe involves the machine sending three packets to each port.
    >
    >
    >--Laura
    >
    >
    >

    _________________________________________________________________
    Don’t just search. Find. Check out the new MSN Search!
    http://search.msn.click-url.com/go/onm00200636ave/direct/01/


  • Next message: James C Slora Jr: "RE: Increase seen in port probes since Tuesday afternoon"

    Relevant Pages

    • Re: Port filtering with IPSEC
      ... I think it makes more sense to have a totally isolated network for infected machines. ... source address - my computer, destination address - any address, source port - any, ... My idea is that if I have to clean out a virus infected machine (and have to ...
      (microsoft.public.windowsxp.security_admin)
    • Re: HTTP connections
      ... On Thu, 19 Jul 2001, Gillard, Paul wrote: ... > attempts from "code red" infected machines? ... I've gone from usually about 0 port 80 ...
      (Incidents)
    • Re: Port 31336 question
      ... I just scanned that port on your machine and it's closed. ... Whoever is doing it may be scanning for infected machines with BO listening ... > someone has been trying port 31336 on my firewall. ... > Linksys router with SPI On and WAN Request blocked on the router. ...
      (comp.security.firewalls)
    • RE: Subseven Scans
      ... They were caught by a IDS product outside of the firewall. ... just port probes. ... were probes to that port. ...
      (Incidents)
    • Re: Port probes tcp 1023
      ... beaker wrote: ... > Any clue to why I am seeing lots of port probes for TCP port 1023? ... The only people for me are the mad ones -- the ones who are mad to live, ...
      (comp.security.misc)