Re: Unusual traffic from UDP 53 to port 0

"Geoffrey Sanders" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Ken:

Might want to try this link. Looks as though what you are seeing may be
virus/trojan related activity. Might want to contact James Affeld (see
posting) and see what his final results were...can't seem to find any
other postings other than what's listed below. Traffic seems similar
though.

http://lists.sans.org/pipermail/list/2004-March/047348.html



<-----Original Message-----> 
From: McKinlay, Ken;McKinlay, Ken
Sent: 9/2/2004 4:20:48 PM
>To: [email protected]
>Subject: Re: [Intrusions] Unusual traffic from UDP 53 to port 0
>
>Folks,
>
>I have been seeing on our external Snort sensor "interesting" traffic
from
>the Internet targeting our end-user NATted address on our firewall. The
>traffic appears to be originating from multiple sources. The packets
details
>are below. I am assuming this is a system scanner attempting to bypass
the
>firewall. This assumption is based on the TTL, the targeting of UDP
port 0
>and the matching of the payload with the ID. 
>
>Is anyone else seeing this and does anyone know what tool is creating
this
>traffic?
>
>Thanks in advance,
>
>Ken McKinlay, GCIA
>Network Security,
>Curtiss-Wright Controls, Embedded Computing
>[email protected] 
>
>----
>
>Traffic Details:
>
>Source IP: various
>Source Port: UDP 53
>Destination IP: firewall (end-user NATted IP address)
>Destination Port: UDP 0
>
>TTL: 1 or 2
>ID: varies
>Packet Length: 64 bytes
>Payload Length: 44
>
>Payload:
>The first 2 bytes are the same as the ID. The next two bytes are always
0x80
>0x81. The rest of the payload is padded with 0x00.
>
>Correlations:
>- 2003-03-31 12:10:33 PST posting to Snort-users mailing list. Subject
"ACID
>snort_archive DB access and udp port 0 traffic" by Jose Ramon Hernandez
>Macias.
>- 2000-09-01 17:57:24 PST posting to comp.protocols.dns.bind. Subject
"DNS
>UDP port 0 activity" by Bruce Hooker.
>- http://www.securiteam.com/securityreviews/5XP0Q2AAKS.html posting on
"Port
>0 OS Fingerprinting".
>- 2004-03-18 03:26 posting on Dshield mailing list
>(http://lists.sans.org/pipermail/list/2004-March/047348.html). Subject
"odd
>udp port 0 traffic" by James Affeld. Note, the payload capture provided
in
>the posting matches what I am seeing at my site.
>- There is a known vulnerability with UDP 0 with Checkpoint firewalls
v3.0
>and v4.0. http://www.osvdb.org/displayvuln.php?osvdb_id=1038.
>
>_______________________________________________
>Intrusions mailing list
>[email protected]
>http://www.dshield.org/mailman/listinfo/intrusions
>. 


<P><font face="Arial, Helvetica, sans-serif" size="2" style="font-size:13.5px">_______________________________________________________________<BR><font face="Arial, Helvetica, sans-serif" size="2" style="font-size:13.5px">Get the FREE email that has everyone talking at <a href="http://www.mail2world.com" target="new">http://www.mail2world.com</a></font><br><br>&nbsp;</font>  </font>
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.