Re: Tons of Source port 80 to random Dest Port Traffic



On 5/18/06, Tom Hayden <haydenth@xxxxxxx> wrote:
Attached is a quick short summary of traffic my server ( xx.xx.xx.xx )
has been bombarded with lately. It's a short dump from tethereal. I
can't seem to figure it out - just tons and tons of traffic coming
from a source port of 80 to seemingly random dest. ports. Can someone
help me identify this?

Thanks!

--
Tom



I wonder if it is a port scan, 'cause what would be the reason for
scanning ports above 1024?

Does the pattern repeat after hours/days ? I mean does "the host
211.7.246.248 *always*
sends a src 80 dest 3509 SYN,ACK packet" after a few hours/days ? If
there is a pattern, then we can be certain of some automation.

-deapesh.



Relevant Pages

  • Re: Exhange 2003 in a DMZ
    ... >I wouldn't recoomend intalling an Exchange Server in the DMZ. ... >to open up tons of ports to your internal network between the two servers. ...
    (microsoft.public.exchange.setup)
  • Re: Port capacity
    ... complex was massive with Liverpool, Birkenhead, Garston, Port Sunlight and the Manchester Ship Canal which is in effect a 35 mile long linear dock, with docks at Manchester holding about 30 ocean going vessels, lay-bys at various points along the canal and docks off the canal at Runcorn and Ellesmere Port. ... Information about British ports is relatively sparce, I had better luck on other areas. ... Total volume in and out was 276 million tons in 1912, ...
    (soc.history.war.world-war-ii)
  • Re: FreeBSD 6 is coming too fast
    ... >> Do not forget about pointyhat which compiles a tons of ports. ...
    (freebsd-current)