Re: UDP traffic on port 48864
"James C Slora Jr" <[email protected]> Tue, 14 Jun 2005 09:28:51 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Organization | PHR+A, pc |
| Message-ID | <[email protected]> |
Andrew Daviel wrote Monday, June 13, 2005 6:42 PM > I've been seeing UDP traffic sent to a host here on port 48864; it seems to all (or mostly) targetted at one particular host, which does not seem to respond (apart from maybe ICMP unreachable). It's from random places on the net (including residential, like P2P), but the packets are quite small (15-500 bytes) and don't seem to have any ASCII content. Packets would be nice. Some trojans calculate the target port from the target IP address, so the port might not be any direct clue. Some examples of what may be similar traffic: http://seclists.org/lists/incidents/2004/Apr/0019.html _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions