tcp 20471 probe?

From: Walter Roberson (roberson@ibd.nrc.ca)
Date: 12/23/01


From: roberson@ibd.nrc.ca (Walter Roberson)
Date: 23 Dec 2001 21:31:55 GMT

Looking through my firewall logs this afternoon, I noticed that
over the last few days, there have been a couple of tries per
hour to contact one of my internal machines [a waste of time, as
the firewall is configured not to let through packets to that address.]

Looking through the logs, I see that the attempts are arriving
from all over the world, and that the destination TCP port number
(i.e., the port number on my end) is random (and sometimes less than 1024).

I also see that the -source- TCP port (the port number
on the end trying to make the connection) is, in each case, one of
20471, 20472, or 21472.

In each case, it is the *same* IP address at my end that is being
targetted.

I find evidence of stray attempts going back at least as far as
September 3rd 2001. I do not, though, see any appreciable number
of probes until Oct 21, 2001. After a series of probes in October,
there was a gap of a couple of weeks before it picks up again
in November. I haven't been probed every day since then, but the rate
has gone up substantially in the last week.

A few entries on roughly September 8th show RST ACK flags on
the incoming packets (but no outgoing packets to that address); other
than that, all the entries show no particular flags -- i.e., the
firewall believes them to be normal TCP connection attempts.

Would anyone have any ideas as to what this traffic might be?



Relevant Pages

  • Re: IPSec NAT Routing etc.
    ... > 101.0/24 is the internal net ... The firewall logs nothing... ... The firewall should log packets that it drops, but in the above case it is ...
    (comp.security.firewalls)
  • Re: W2K IIS under attack
    ... You need to determine the nature fo those packets... ... You NEED NEED NEED a firewall, if not for protection, then ... If you have no firewall logs, ... > computer form other computers under the local network. ...
    (microsoft.public.inetserver.iis.security)
  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: Visnetic and 8signs firewall LOOPHOLE Read....
    ... I said I am just reporting bug in your Firewall, ... From the Port Scan/Properties control screen: ... The firewall filtered 100% of the packets that were received. ... operating system (I'm talking Windows, ...
    (comp.security.firewalls)