Re: Increase in UDP Port Scans

From: Ranjeet Shetye (ranjeet.shetye2_at_zultys.com)
Date: 08/12/03

  • Next message: Mike West: "Getting In"
    To: security-basics@securityfocus.com
    Date: 11 Aug 2003 16:25:41 -0700
    
    

    On Mon, 2003-08-11 at 08:19, Gordon Brandt wrote:
    > I have noticed the following port scans lately on my network
    >
    > 08/11/2003 05:14:22.112 - Possible Port Scan - Source:24.52.108.213, 1745,
    > WAN - Destination:255.255.255.255, 7782, LAN - UDP scanned port list,
    > 8777, 8777, 7778, 7779, 7780 -
    > 08/11/2003 05:14:22.128 - Probable Port Scan - Source:24.52.108.213, 1745,
    > WAN - Destination:255.255.255.255, 7787, LAN - UDP scanned port list,
    > 8777, 8777, 7778, 7779, 7780, 7781, 7782, 7783, 7784, 7785 -
    >
    >
    > I did a little digging with google, and it appears that these ports are used
    > by Unreal Tournament servers. So, after seeing this, I relaxed a little
    > thinking that someone had just gotten a new game. This morning, I checked
    > my email, and I have a significant amount of these messages, coming into
    > different branch offices (we use cable/dsl for internet access) so it can't
    > just be one person with a new pc.
    >
    > Anyone else seeing this?
    >
    > Gordon Brandt
    > Network Engineer
    > AP Wagner, Inc.
    > gbrandt@apwagner.com
    >
    >
    > ---------------------------------------------------------------------------
    > ----------------------------------------------------------------------------

    Not to deflect attention from any possible intrusion attempts, but if
    this happens primarily over the weekends or after-hours, your office
    might be inhabitated by a bunch of gamers who cannot afford broadband at
    home, and are using the office high speed connections to get their fix.
    :D

    Since I play UT once in a while (on my home DSL), I can understand their
    need for a low ping.

    -- 
    Ranjeet Shetye
    Senior Software Engineer
    Zultys Technologies
    Ranjeet dot Shetye2 at Zultys dot com
    http://www.zultys.com/
     
    The views, opinions, and judgements expressed in this message are solely
    those of the author. The message contents have not been reviewed or
    approved by Zultys.
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Mike West: "Getting In"

    Relevant Pages

    • RE: Printing from Win9x clients stops
      ... > and make sure this software does not interfere with SBS Server. ... > clients, please disable it and try again. ... Create a local printer and redirect the port to the network server. ...
      (microsoft.public.windows.server.sbs)
    • RE: SBS 2003, ISA 2004
      ... ISA and IIS try listening on these two ports. ... by default the Web Proxy is listening on port 8080 ... of the local network adapter. ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Re: ERS 8600, simple setup, IP, VLANs, etc.
      ... management port is just used to hang an IP address to. ... associated with an interface, such as a VLAN. ... fairly functionally homogenous network), but something that is ... or OS virtuallization - except that networks have been doing this kind of ...
      (comp.dcom.sys.nortel)
    • network slowness/freez-up since update 10/11
      ... network problems: first the network is slow (even within a few ... network - but not the rest of the system - just locks up (can't ping ... OHCI version 1.0, legacy support ... <Parallel port bus> on ppc0 ...
      (freebsd-current)
    • network slowness/freez-up since update 10/11
      ... network problems: first the network is slow (even within a few ... network - but not the rest of the system - just locks up (can't ping ... OHCI version 1.0, legacy support ... <Parallel port bus> on ppc0 ...
      (freebsd-current)