Re: What to look at, source or destination port?

From: José Joaquín (jostein_svq_at_hotmail.com)
Date: 07/23/03

  • Next message: ~Kevin Davis³: "Re: Microsot Liability for vulnerabilities"
    To: nathan.grandbois@cerdant.com, security-basics@securityfocus.com
    Date: Wed, 23 Jul 2003 08:32:15 +0200
    
    

    Hi there,

    UDP is not a connection-oriented protocol as TCP is, so it is more difficult
    to track it by a mean firewall (i.e. it's quite difficult to find out which
    peer is the origin of the communication). You should determine if there is
    more entries in the logs like those, group them by source port and see if
    the destination port it's the same.

    Anyway it's a good practice to allow to pass through the firewall only
    packets belonging to well known UDP protocols.

    I hope this information is useful to you.

    Best regards,
    Jose Joaquin.

    >From: "Nathan" <nathan.grandbois@cerdant.com>
    >Reply-To: <nathan.grandbois@cerdant.com>
    >To: <security-basics@securityfocus.com>
    >CC: <firewalls@securityfocus.com>
    >Subject: What to look at, source or destination port?
    >Date: Tue, 22 Jul 2003 12:57:06 -0400
    >
    >07/19/2003 04:33:30.688 - UDP packet dropped - Source:10.30.9.60, 1042,
    >LAN - Destination:remote.ip.address.x, 1948, WAN - -
    >07/19/2003 04:35:48.912 - UDP packet dropped - Source:10.30.9.60, 1042,
    >LAN - Destination:remote.ip.address.x, 1948, WAN - -
    >07/19/2003 04:37:34.384 - UDP packet dropped - Source:10.30.9.60, 1042,
    >LAN - Destination:remote.ip.address.x, 1948, WAN - -
    >07/19/2003 04:40:41.576 - UDP packet dropped - Source:10.30.9.60, 1042,
    >LAN - Destination:remote.ip.address.x, 1948, WAN - -
    >07/19/2003 03:16:22.432 - UDP packet dropped - Source:10.30.9.60, 1042,
    >LAN - Destination:remote.ip.address.x, 1948, WAN - -
    >
    >I recently saw these logs come across my friends firewall. I'm trying to
    >determine what is going on here. I looked up the remote.ip.address.x and it
    >was a AT&T Worldnet user. The destination port, 1948, is listed as eye2eye.
    >Well, I looked at eye2eye's website (www.iosoftware.com) and found nothing
    >about 1948. A user would have to configure the securesite software to use
    >that port specifically - which is not the case. My question to the list is,
    >is the source port what I should be looking at in these connections, or the
    >destination port?
    >
    >-Nathan
    >

    _________________________________________________________________
    Localiza y ponte en contacto con tus antiguos compañeros de clase en MSN
    Compañeros. http://mipasado.msn.es/

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: ~Kevin Davis³: "Re: Microsot Liability for vulnerabilities"

    Relevant Pages

    • Re: Need Some help with Instrument Control toolbox
      ... No inherent sequence numbers, no inherent ACK or NAK, no inherent detection of lost data, no inherent protocol to follow to set up or close down a connection; if these are potential problems then you have to put them into the UDP packet yourself, re-inventing parts of TCP. ... The difficulty is that Matlab is not able to act as a TCP server -- which means that it is not able to respond when something else initiates a TCP/IP connection. ... Using the same source and destination port is not uncommon for simple interfaces, but such a configuration is not used if there need to be multiple systems talking to the same service: each distinct conversation needs to have its own source port. ...
      (comp.soft-sys.matlab)
    • Re: Remote Desktop on SBS2003
      ... For internet access you would need to configure your firewall to only allow ... access to destination port 3389 TCP from a specific IP address. ... I allowed to use Remote Desktop. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: NAT the Destination Port
      ... 162 is the destination port as seen ... even though the access-list on the firewall states 90000. ... Notice that static would -normally- have the interface order ... In reverse statics, the ...
      (comp.dcom.sys.cisco)
    • Re: blocking incoming udp packets
      ... It seems the router is sending udp packets to 255.255.255.255 (both ... and destination port 162. ... UDP 162 is the SNMP trap port. ... network device attempting to send traps to be logged by an SNMP ...
      (comp.security.firewalls)
    • Re: blocking incoming udp packets
      ... It seems the router is sending udp packets to 255.255.255.255 (both ... and destination port 162. ... UDP 162 is the SNMP trap port. ... network device attempting to send traps to be logged by an SNMP ...
      (comp.security.firewalls)