Increase in UDP Port Scans

From: Gordon Brandt (gbrandt_at_apwagner.com)
Date: 08/11/03

  • Next message: Tim Donahue: "RE: Modem connection"
    To: <security-basics@securityfocus.com>
    Date: Mon, 11 Aug 2003 11:19:06 -0400
    
    

    I have noticed the following port scans lately on my network

    08/11/2003 05:14:22.112 - Possible Port Scan - Source:24.52.108.213, 1745,
    WAN - Destination:255.255.255.255, 7782, LAN - UDP scanned port list,
    8777, 8777, 7778, 7779, 7780 -
    08/11/2003 05:14:22.128 - Probable Port Scan - Source:24.52.108.213, 1745,
    WAN - Destination:255.255.255.255, 7787, LAN - UDP scanned port list,
    8777, 8777, 7778, 7779, 7780, 7781, 7782, 7783, 7784, 7785 -

    I did a little digging with google, and it appears that these ports are used
    by Unreal Tournament servers. So, after seeing this, I relaxed a little
    thinking that someone had just gotten a new game. This morning, I checked
    my email, and I have a significant amount of these messages, coming into
    different branch offices (we use cable/dsl for internet access) so it can't
    just be one person with a new pc.

    Anyone else seeing this?

    Gordon Brandt
    Network Engineer
    AP Wagner, Inc.
    gbrandt@apwagner.com

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Tim Donahue: "RE: Modem connection"

    Relevant Pages

    • Re: General questions about Sockets
      ... > could I push it before I see the network slowing down and/or errors? ... Nagle/Delayed ACK interaction but you could confirm it with a packet ... > I can setup any port in my registry, but what would be the 'default' one I ... Google could confirm it. ...
      (microsoft.public.win32.programmer.networks)
    • help: using smtp.gmail.com as SMART_HOST
      ... with my Google gmail address. ... is pop.gmail.com, using port 995. ... Retrieving mail is not the problem since my Google searches ... client, I believe the term is) to send my mail to Google's ...
      (comp.mail.sendmail)
    • Why Google Will Kill Node Computing
      ... Why Google Will Kill Node Computing ... Twenty years ago, personal computers became the ... most advanced human communication system in widespread use. ... of the art human communication network. ...
      (comp.programming)
    • RE: SBS 2003, ISA 2004
      ... ISA and IIS try listening on these two ports. ... by default the Web Proxy is listening on port 8080 ... of the local network adapter. ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Re: ERS 8600, simple setup, IP, VLANs, etc.
      ... management port is just used to hang an IP address to. ... associated with an interface, such as a VLAN. ... fairly functionally homogenous network), but something that is ... or OS virtuallization - except that networks have been doing this kind of ...
      (comp.dcom.sys.nortel)