Re: UDP traffic on port 48864
Joel Esler <[email protected]> Mon, 13 Jun 2005 18:57:51 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
The only hits I have on the port are Source Ports, so I can't help you there :) Sorry :( Joel On 6/13/05, Andrew Daviel <[email protected]> wrote: > > I've been seeing UDP traffic sent to a host here on port 48864; it seems > to all (or mostly) targetted at one particular host, which does not seem > to respond (apart from maybe ICMP unreachable). It's from random places > on the net (including residential, like P2P), but the packets are quite > small (15-500 bytes) and don't seem to have any ASCII content. > > I found it by accident; a machine offsite sent a virus to our mailserver > and also to this host (which does not do mail) and when I looked back saw > this UDP stuff. The user has run things like skype and itunes, but no > P2P and the machine appears to be clean (Symantec, Microsoft > anti-spyware) > > Any ideas ? I can publish some data if it's useful. > > .. I did look on Google and a couple of port lists but nothing caught my > eye. > > > -- > Andrew Daviel, TRIUMF, Canada > Tel. +1 (604) 222-7376 (Pacific Time) > [email protected] > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions