Re: Port Scan(?)

From: jklemenc@fnal.gov
Date: 03/21/02


To: Adrian Horton <adhort02@yahoo.com>
From: jklemenc@fnal.gov
Date: Thu, 21 Mar 2002 13:28:24 -0600


Sonicwall IRE VPN Client perhaps? Look for IREike.exe in the Task Manager's
process list.

Joe

                                                                                                                                           
                      Adrian Horton
                      <adhort02@yahoo.c To: security-basics@securityfocus.com
                      om> cc:
                                               Subject: Port Scan(?)
                      03/20/2002 01:41
                      PM
                                                                                                                                           
                                                                                                                                           

The incidents@securityfocus.com owner rejected this
post so can anyone here make sense of this?

On my 10.1.2.0/24 network, I discovered (with
Ethereal) that one of my hosts (10.1.2.112) was
broadcasting UDP packets to 255.255.255.255 to port
62516.
The *source port* though was incrementing by one after
every packet. That host machine is running Windows
2000.

Anyone know what kind of activity this is? It seems
the opposite of a port scan and it is inside my
private network. I know which machine it is, I just
can't figure out what it was doing so I disconnected
it from the network until I figure it out.

Thanks,

AH

__________________________________________________
Do You Yahoo!?
Yahoo! Sports - live college hoops coverage
http://sports.yahoo.com/



Relevant Pages

  • re: port 42510
    ... > would be doing open on a number of machines in my ... > office's network. ... open port to the process using it... ... Do You Yahoo!? ...
    (Security-Basics)
  • Re: Truly bizarre NIC (?) problem
    ... I did consider the port speed when I first ... says that the Network people do not know where each ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (AIX-L)
  • RE: Port 2/tcp.
    ... network, and finds an unusual port open...even ... w/ configurable/random port bindings, they still ... Do you Yahoo!? ...
    (Security-Basics)
  • RE: Printing from Win9x clients stops
    ... > and make sure this software does not interfere with SBS Server. ... > clients, please disable it and try again. ... Create a local printer and redirect the port to the network server. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2003, ISA 2004
    ... ISA and IIS try listening on these two ports. ... by default the Web Proxy is listening on port 8080 ... of the local network adapter. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)