Unusual traffic from UDP 53 to port 0
"McKinlay, Ken" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <C30BFF3D82EAD611824000065BEDE17103488109@DY4EXSRV4> |
Folks, I have been seeing on our external Snort sensor "interesting" traffic from the Internet targeting our end-user NATted address on our firewall. The traffic appears to be originating from multiple sources. The packets details are below. I am assuming this is a system scanner attempting to bypass the firewall. This assumption is based on the TTL, the targeting of UDP port 0 and the matching of the payload with the ID. Is anyone else seeing this and does anyone know what tool is creating this traffic? Thanks in advance, Ken McKinlay, GCIA Network Security, Curtiss-Wright Controls, Embedded Computing [email protected] ---- Traffic Details: Source IP: various Source Port: UDP 53 Destination IP: firewall (end-user NATted IP address) Destination Port: UDP 0 TTL: 1 or 2 ID: varies Packet Length: 64 bytes Payload Length: 44 Payload: The first 2 bytes are the same as the ID. The next two bytes are always 0x80 0x81. The rest of the payload is padded with 0x00. Correlations: - 2003-03-31 12:10:33 PST posting to Snort-users mailing list. Subject "ACID snort_archive DB access and udp port 0 traffic" by Jose Ramon Hernandez Macias. - 2000-09-01 17:57:24 PST posting to comp.protocols.dns.bind. Subject "DNS UDP port 0 activity" by Bruce Hooker. - http://www.securiteam.com/securityreviews/5XP0Q2AAKS.html posting on "Port 0 OS Fingerprinting". - 2004-03-18 03:26 posting on Dshield mailing list (http://lists.sans.org/pipermail/list/2004-March/047348.html). Subject "odd udp port 0 traffic" by James Affeld. Note, the payload capture provided in the posting matches what I am seeing at my site. - There is a known vulnerability with UDP 0 with Checkpoint firewalls v3.0 and v4.0. http://www.osvdb.org/displayvuln.php?osvdb_id=1038. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions