Re: Increase seen in port probes since Tuesday afternoon

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 12/31/04


Date: Thu, 30 Dec 2004 23:32:14 -0500
To: James C Slora Jr <Jim.Slora@phra.com>

James C Slora Jr wrote:
> BahdKo wrote Thursday, December 30, 2004 04:23
>>Since Tuesday afternoon EST I've seen a dramatic increase in
>>the number of machines probing my network on ports 2745,
>>1025, 3127, 6129, and usually 80. Each probe involves the
>>machine sending three packets to each port.
>
> Yes from time to time. The port pattern is typical of many botnets, many of
> which will focus multiple drones against a particular IP space for a while.

I'm seeing 80, 1025, 6129, and 1433 increases in tcp, and 1434, 1026,
and 1027 udp. The usual 135/445 are present as always but I haven't
paid much attention to a 'marked increase' as they long ago drifted into
the pool of "background noise".

Jeff



Relevant Pages

  • RE: Printing from Win9x clients stops
    ... > and make sure this software does not interfere with SBS Server. ... > clients, please disable it and try again. ... Create a local printer and redirect the port to the network server. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2003, ISA 2004
    ... ISA and IIS try listening on these two ports. ... by default the Web Proxy is listening on port 8080 ... of the local network adapter. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: ERS 8600, simple setup, IP, VLANs, etc.
    ... management port is just used to hang an IP address to. ... associated with an interface, such as a VLAN. ... fairly functionally homogenous network), but something that is ... or OS virtuallization - except that networks have been doing this kind of ...
    (comp.dcom.sys.nortel)
  • network slowness/freez-up since update 10/11
    ... network problems: first the network is slow (even within a few ... network - but not the rest of the system - just locks up (can't ping ... OHCI version 1.0, legacy support ... <Parallel port bus> on ppc0 ...
    (freebsd-current)
  • network slowness/freez-up since update 10/11
    ... network problems: first the network is slow (even within a few ... network - but not the rest of the system - just locks up (can't ping ... OHCI version 1.0, legacy support ... <Parallel port bus> on ppc0 ...
    (freebsd-current)