RE: Tons of Source port 80 to random Dest Port Traffic



I see that all the time, mostly SYN-ACK packets (i.e., looks
like a response from a server to a machine on my network, except
where's the SYN from my net?).

Possibility 1:

Remote servers are under SYN-flood attack using spoofed source
addresses. Since your address was spoofed, you get the attacked
server's reesponse attempt(s).

Possibility 2:

I have occasionally seen IE appear to get fooled by this, and
enter into a TCP session that it didn't really initiate. This
might be an attack verctor against other IE bugs.

David Gillett



-----Original Message-----
From: thayden@xxxxxxxxx [mailto:thayden@xxxxxxxxx] On Behalf
Of Tom Hayden
Sent: Thursday, May 18, 2006 8:03 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Tons of Source port 80 to random Dest Port Traffic

Attached is a quick short summary of traffic my server (
xx.xx.xx.xx ) has been bombarded with lately. It's a short
dump from tethereal. I can't seem to figure it out - just
tons and tons of traffic coming from a source port of 80 to
seemingly random dest. ports. Can someone help me identify this?

Thanks!

--
Tom




Relevant Pages

  • Tons of Source port 80 to random Dest Port Traffic
    ... Attached is a quick short summary of traffic my server ... It's a short dump from tethereal. ... can't seem to figure it out - just tons and tons of traffic coming ... from a source port of 80 to seemingly random dest. ...
    (Security-Basics)
  • [NT] Web Browsers Vulnerable to the Extended HTML Form Attack
    ... inject HTML scripts, which makes use of the same method described in the ... The Original HTML form attack: ... server 7 open ...
    (Securiteam)
  • [UNIX] DoS Attack Against FreeRADIUS (Other RADIUS Servers Affected)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... to create a high-performance and highly configurable GPL'd RADIUS server. ... program with failed requests causing a denial of service attack. ... Access-Request to the RADIUS server, ...
    (Securiteam)
  • Re: I was hacked
    ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
    (alt.computer.security)
  • Re: I was hacked
    ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
    (microsoft.public.inetserver.iis.security)