Re: Unusual traffic from UDP 53 to port 0

"Michael Fischer" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Two possible tools being used:
Someone's using hping2 in an attempt to map out your perimeter and/or
firewall rulesets. Hping2 is a very easy to use pinger with flexible
options. One of the standard recommendations for it is to try a source
of 53 UDP, and it's defautl destination is port 0. If it is someone
using hping2, they may also be trying other settings (flags set, UDP or
TCP to misc. ports) to see if they can't get through your firewall --
they're simply probing for a weak spot.  http://www.hping.org/ for more
info.

Someone's using firewalk to probe your perimeter. 
http://www.packetfactory.net/Projects/firewalk/
If I remember right, firewalk uses UDP 53 and ICMP_TIME_EXCEEDED.  A
possibility...

HTH, Cheers!

>>> [email protected] 09/02/04 10:10 AM >>>
Folks,

I have been seeing on our external Snort sensor "interesting" traffic
from
the Internet targeting our end-user NATted address on our firewall. The
traffic appears to be originating from multiple sources. The packets
details
are below. I am assuming this is a system scanner attempting to bypass
the
firewall. This assumption is based on the TTL, the targeting of UDP port
0
and the matching of the payload with the ID. 

Is anyone else seeing this and does anyone know what tool is creating
this
traffic?

Thanks in advance,

Ken McKinlay, GCIA
Network Security,
Curtiss-Wright Controls, Embedded Computing
[email protected] 

----

Traffic Details:

Source IP:		various
Source Port:	UDP 53
Destination IP:	firewall (end-user NATted IP address)
Destination Port:	UDP 0

TTL:			1 or 2
ID:			varies
Packet Length:	64 bytes
Payload Length:	44

Payload:
The first 2 bytes are the same as the ID. The next two bytes are always
0x80
0x81. The rest of the payload is padded with 0x00.

Correlations:
- 2003-03-31 12:10:33 PST posting to Snort-users mailing list. Subject
"ACID
snort_archive DB access and udp port 0 traffic" by Jose Ramon Hernandez
Macias.
- 2000-09-01 17:57:24 PST posting to comp.protocols.dns.bind. Subject
"DNS
UDP port 0 activity" by Bruce Hooker.
- http://www.securiteam.com/securityreviews/5XP0Q2AAKS.html posting on
"Port
0 OS Fingerprinting".
- 2004-03-18 03:26 posting on Dshield mailing list
(http://lists.sans.org/pipermail/list/2004-March/047348.html). Subject
"odd
udp port 0 traffic" by James Affeld. Note, the payload capture provided
in
the posting matches what I am seeing at my site.
- There is a known vulnerability with UDP 0 with Checkpoint firewalls
v3.0
and v4.0. http://www.osvdb.org/displayvuln.php?osvdb_id=1038.

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.