Re: Port Scanning on 1026 & 1027

"Earnhart, Benjamin J" <[email protected]> Wed, 27 Jul 2005 10:29:36 -0500
Newsgroups gmane.comp.security.intrusions
Message-ID <4F5CA8D7D1561B45A128D35DB86BA8F8028E07E6@IOWAEVS03.iowa.uiowa.edu>
Same here, lately 1026 and 1027 have become as popular as 1433 and 22.

I assumed it was people trying to get by blocks on the regular MS SMB
ports (135-139 and 445).  I *think* it should *mostly* be a non-issue,
since AFAIK, 1026 and 1027 only get opened up temporarily when
authenticating and establishing a connection, so an attacker would have
to have perfect timing and an unpatched machine to attack.  But if it
really is that much of a no-big-deal thing, I don't get why the bad guys
are bothering with it.

So I concur with you that they're becoming very popular, and look
forward to somebody giving a decent explanation as to why this is
happening.

*==========================================;
*Ben Earnhart
*Computer Consultant and 
*ICPSR Representative
*Department of Sociology and 
*College of Liberal Arts
*University of Iowa
*(319) 335-2887
*[email protected]
*==========================================; 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Tony Tomasello
> Sent: Tuesday, July 26, 2005 2:15 PM
> To: [email protected]
> Subject: [Intrusions] Port Scanning on 1026 & 1027
> 
> Guys,
> 
> I have noticed a tremendous amount of scanning on ports 1026 
> and 1027. Not 
> sure if you all have been experiencing the same. Is this 
> something that I 
> should be concerned about ?
> 
> Thanks,
> Tony T.
> 
> 
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions