RE: Unusual traffic from UDP 53 to port 0
"McKinlay, Ken" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <C30BFF3D82EAD611824000065BEDE17103488110@DY4EXSRV4> |
Michael, Thanks for the suggestions. I've downloaded, compiled and run both hping2 and firewalk. Both, although the port 0 scans work, don't exhibit the same packet output that I am seeing in the payload. That is, the IP ID of the packet in the first two bytes of the payload. Using hping2 2.0 rc3 I was able to keep the source and destination ports constant and have the scan work like traceroute (TTLs), I could not figure how to get the payload to contain the IP ID followed by 0x81 0x80. With firewalk, although the first packet can be set to a destination of UDP 0, I was not able to have the packets after that keep that destination ports. The destination port address kept incrementing. Again, this does not match what I am seeing in my logs and at my firewall. Ken McKinlay, GCIA Network Security, Curtiss-Wright Controls, Embedded Computing [email protected] > -----Original Message----- > From: Michael Fischer [mailto:[email protected]] > Sent: Friday, September 03, 2004 9:05 AM > To: [email protected]; [email protected] > Subject: Re: [Intrusions] Unusual traffic from UDP 53 to port 0 > > > Two possible tools being used: > Someone's using hping2 in an attempt to map out your perimeter and/or > firewall rulesets. Hping2 is a very easy to use pinger with flexible > options. One of the standard recommendations for it is to try a source > of 53 UDP, and it's defautl destination is port 0. If it is someone > using hping2, they may also be trying other settings (flags > set, UDP or > TCP to misc. ports) to see if they can't get through your firewall -- > they're simply probing for a weak spot. > http://www.hping.org/ for more > info. > > Someone's using firewalk to probe your perimeter. > http://www.packetfactory.net/Projects/firewalk/ > If I remember right, firewalk uses UDP 53 and ICMP_TIME_EXCEEDED. A > possibility... > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions