Re: Who is looking for port 2036?

From: Tillmann Werner (tillmann.werner_at_gmx.de)
Date: 10/26/05

  • Next message: Daniel Cid: "Re: SSH bruteforce on its way..."
    To: incidents@securityfocus.com
    Date: Wed, 26 Oct 2005 21:48:53 +0200
    
    

    Joakim,

    > The scan seems to be from a large botnet, across the world.

    What makes you believe the attack's origin is a botnet?

    > They have only targeted one ip, and it doesn't respond to those ports.

    Your samples only showed port 2036/tcp on a very low frequency. Is this
    representative for a longer period? What is the percentage of port 80/tcp
    packets?

    > Is it the tryout of a new worm?

    Unlikely, if it only targets a single ip address which does not respond. Http
    might be used as destination port for such packets are likely to go through
    firewalls.

    If you are interested in furhter investigation, you could run netcat on the
    attacked host to see if connection establishment goes on and if there arrives
    any data.

    Tillmann


  • Next message: Daniel Cid: "Re: SSH bruteforce on its way..."

    Relevant Pages

    • Re: What is going on with my Dialup?
      ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
      (comp.os.linux.networking)
    • Re: OT .. Road Warrior communications question
      ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
      (alt.guitar.bass)
    • Re: Logs: Many hits with source port of 80
      ... The hits from source port 80 to dest port 37852 are IMHO almost ... you should probably see a couple other packets - perhaps ... packets if either you send the load balancer a packet, ... >>I have seen similar hits for the past three months. ...
      (Incidents)
    • Re: Error 720 connecting to server via VPN
      ... By default the router's firewall is configured to drop ICMP packets ... Select WAN Setup> Advanced> Respond to Ping on Internet Port. ... server and the Internet allow GRE packets. ... routers on the user's network are also configured to allow GRE packets. ...
      (microsoft.public.windows.server.sbs)
    • Re: WORM? ... server generating NBT-NS (port 137) traffic on WAN interface
      ... You have a concern about the outbound port 137 traffic in the SBS domain. ... The UDP 137 is related to the NetBIOS Over TCP/IP name service. ... I did run NETMON on the SBS2003 box, it did find the extraneous packets ... ... connected to the Internet (If the SBS server is the 2 NICs scenario). ...
      (microsoft.public.windows.server.sbs)