Re: UDP traffic on port 48864

Joel Esler <[email protected]> Mon, 13 Jun 2005 18:57:51 -0400
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
The only hits I have on the port are Source Ports, so I can't help you there 
:)

Sorry :(

Joel

On 6/13/05, Andrew Daviel <[email protected]> wrote:
> 
> I've been seeing UDP traffic sent to a host here on port 48864; it seems
> to all (or mostly) targetted at one particular host, which does not seem
> to respond (apart from maybe ICMP unreachable). It's from random places
> on the net (including residential, like P2P), but the packets are quite
> small (15-500 bytes) and don't seem to have any ASCII content.
> 
> I found it by accident; a machine offsite sent a virus to our mailserver
> and also to this host (which does not do mail) and when I looked back saw
> this UDP stuff. The user has run things like skype and itunes, but no
> P2P and the machine appears to be clean (Symantec, Microsoft
> anti-spyware)
> 
> Any ideas ? I can publish some data if it's useful.
> 
> .. I did look on Google and a couple of port lists but nothing caught my
> eye.
> 
> 
> --
> Andrew Daviel, TRIUMF, Canada
> Tel. +1 (604) 222-7376 (Pacific Time)
> [email protected]
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
>
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions