RE: Port 13227
"Mark Hofman" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Mmmm, Bummer was kinda hoping for an easy answer :-) Scanned the network today and didn't strike anything on the port. I'll have to do some more digging. It's a DHCP location so I might just drop the link and get a new address and see if it picks up again. If it starts up again that should show me there is a problem on one of the two internal segments behind the fw. Thanks again Mark -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Kyle Maxwell Sent: Tuesday, 21 September 2004 7:16 AM To: Intrusions List (GCIA Practicals) Subject: Re: [Intrusions] Port 13227 On Mon, 20 Sep 2004 11:13:07 +1000, Mark Hofman <[email protected]> wrote: > One of our customers is getting quite a number of hits on port > TCP/13227 on their firewalls. The source seems to be mainly dail-in > and ADSL machines from a wide range of locations (so far US, Europe, > NZ and local). It is mainly to one specific location, but from the > logs it doesn't seem to be in response to anything. > > Anybody seen anything similar or know what they might be looking for > on this port? Can he set up a listener on an isolated host and get a packet capture? Does he have any internal applications that use that port? If practical, can he scan his internal network for systems listening on that port (to investigate them further)? Just some thoughts, we haven't seen anything that I'm aware of. -- Kyle Maxwell [[email protected]] _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions