RE: Unusual traffic from UDP 53 to port 0

"McKinlay, Ken" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <C30BFF3D82EAD611824000065BEDE17103488110@DY4EXSRV4>
Michael,

Thanks for the suggestions. I've downloaded, compiled and run both hping2
and firewalk. Both, although the port 0 scans work, don't exhibit the same
packet output that I am seeing in the payload. That is, the IP ID of the
packet in the first two bytes of the payload.

Using hping2 2.0 rc3 I was able to keep the source and destination ports
constant and have the scan work like traceroute (TTLs), I could not figure
how to get the payload to contain the IP ID followed by 0x81 0x80. With
firewalk, although the first packet can be set to a destination of UDP 0, I
was not able to have the packets after that keep that destination ports. The
destination port address kept incrementing. Again, this does not match what
I am seeing in my logs and at my firewall.


Ken McKinlay, GCIA
Network Security,
Curtiss-Wright Controls, Embedded Computing
[email protected] 


> -----Original Message-----
> From: Michael Fischer [mailto:[email protected]]
> Sent: Friday, September 03, 2004 9:05 AM
> To: [email protected]; [email protected]
> Subject: Re: [Intrusions] Unusual traffic from UDP 53 to port 0
> 
> 
> Two possible tools being used:
> Someone's using hping2 in an attempt to map out your perimeter and/or
> firewall rulesets. Hping2 is a very easy to use pinger with flexible
> options. One of the standard recommendations for it is to try a source
> of 53 UDP, and it's defautl destination is port 0. If it is someone
> using hping2, they may also be trying other settings (flags 
> set, UDP or
> TCP to misc. ports) to see if they can't get through your firewall --
> they're simply probing for a weak spot.  
> http://www.hping.org/ for more
> info.
> 
> Someone's using firewalk to probe your perimeter. 
> http://www.packetfactory.net/Projects/firewalk/
> If I remember right, firewalk uses UDP 53 and ICMP_TIME_EXCEEDED.  A
> possibility...
> 
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.