Re: port 666 from router

"Adam Pavelec" <apavelec-be0aN53zdcR+u43qRgrggVaTQe2KTcn/@public.gmane.org> Thu, 18 Nov 2004 12:28:02 -0500
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <00f401c4cd93$f7e58fc0$2027a8c0@PAVELECA>
On Thursday, November 18, 2004 10:56 AM [GMT-5=EST], Glen Dady 
<[email protected]> wrote:

> It is probably a good idea for everyone to block port 666.  To the
> best of my knowledge it's not used by any legitimate service.  Also
> it would be a good thing to add to the next update file.

Why?  By default, port 666/TCP is not enabled as an External Service rule, 
nor as a forwarded port.  An update that arbitrarily modifies firewall rules 
would probably be a really bad idea.

As Martin mentioned in a previous post, it is very likely that a node on the 
internal network has been infected with some sort of trojan.  Without more 
detailed information from the original poster, it's really hard to come to 
any conclusions as to what exactly is happening.  Upon deciphering the 
original message, it appears to read that the firewall log is showing 
something like:

___________________________________________________________

Time        In  Out Proto   Source          Destination
hh:mm:ss    ?   ?   TCP     smoothwall:666  smoothwall:1026
___________________________________________________________


without 'sendhere-tUwO18uD7CBWk0Htik3J/[email protected]' postin ne furtha nfo, it'a be hard 4 anyboyd 
2 help ne mor dan dis 
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall