Possible probe of port 137 using udp 50?????

From: Stefan Osterlitz (ostrlitz@blox.de)
Date: 08/14/01


From: "Stefan Osterlitz" <ostrlitz@blox.de>
To: <SECURITY-BASICS@securityfocus.com>
Subject: Possible probe of port 137 using udp 50?????
Date: Tue, 14 Aug 2001 19:29:41 +0200
Message-ID: <C5FEADB4FB3EE543959CE43DEE2ABE4E35F3@trendserver.blox.blox.ag>


Hi Everybody,

        Just got a quick question. I was reviewing logs on my shadow box
and noticed that for a period of a couple hours we had packet
conversation
between two hosts ( one local and one remote ) through port 137 using
udp
50. My PIX acl's dont have any ruleset to allow this network in at
all
except through say port 80 to our web servers. Is this a known attack
or
probe? Thanks.

This should not get thru if your firewall is well configured.
UDP 50 is a port for IPSEC (virtual private networking).
Win2K Machines send them when they try to establish a secure
connection.

what do you mean by "through udp 50"?
137 --> udp 50 tunnel --> somewhere else ?
(tcp?) 137 --> udp 50 ?
udp 50 --> ?

Try to post a line from your packet log, please.

Stefan Osterlitz



Relevant Pages

  • Re: UDP to port 1027
    ... directing you to go to some spammers website where FOR ONLY US$29.95 plus ... just because someone tried to connect to port X only ... That's a guess based on the size of the packet. ... Undelivered UDP ...
    (comp.security.firewalls)
  • Re: Blocking Ports 137 to 139
    ... > DNS uses the UDP protocol, ... > inbound UDP from Port 53 to any dynamic high port. ... > can also limit it to the application making the request. ... > be open for the UDP packet at that local port is the one making the original ...
    (comp.security.firewalls)
  • Re: [fw-wiz] udp port 0
    ... I believe this is a feature of IOS. ... port numbers, they are logged as port 0. ... UDP in general, IOS doesn't have to check the port number for a decision ... whether to block or accept the packet. ...
    (Firewall-Wizards)
  • Re: bind() udp behavior 2.6.8.1
    ... > any firewall must keep some sort of state table even if it is udp. ... > numbered port is making a udp dns request, and thus be able to allow ... table entry, then forwarded the packet. ... successfully manage a multitude of UDP connections, ...
    (Linux-Kernel)
  • [Full-Disclosure] Increase probe on UDP port 1026
    ... During the last a few hours, I've seen a huge jump in traffic to UDP ... port 1026. ... One interesting pattern that I found out from the packet that Snort ...
    (Full-Disclosure)