Port 10099?

Paul Howarth <[email protected]> Thu, 17 Mar 2005 16:50:16 +0000
Newsgroups gmane.mail.spam.dsbl.general
Message-ID <[email protected]>
This morning a received a substantial batch of pump'n'dump scam spams 
from a variety of what I presumed were open proxies. However, most of 
them didn't seem to have any open proxies there. One thing that appeared 
very commonly though was an open port 10099, though it consistently 
refuses proxy connections:

$ pxtest -v -p10099 -M1 67.177.49.30
To check: hosts=1, proto:ports=7, host:proto:ports=7
67.177.49.30:s5:10099: EOF
67.177.49.30:s4:10099: EOF
67.177.49.30:hc:10099: >> CONNECT 205.231.29.241:25 HTTP/1.0\r\n
67.177.49.30:hc:10099: >> \r\n
67.177.49.30:hc:10099: >> HELO [67.177.49.30]\r\n
67.177.49.30:hc:10099: EOF
67.177.49.30:ho:10099: >> POST http://205.231.29.241:25/ HTTP/1.0\r\n
67.177.49.30:ho:10099: >> Content-length: 390\r\n
67.177.49.30:ho:10099: >> Connection: close\r\n
67.177.49.30:ho:10099: >> \r\n
67.177.49.30:ho:10099: sending data
67.177.49.30:ho:10099: EOF
67.177.49.30:wg:10099: EOF
67.177.49.30:hu:10099: >> PUT http://205.231.29.241:25/ HTTP/1.0\r\n
67.177.49.30:hu:10099: >> Content-length: 388\r\n
67.177.49.30:hu:10099: >> Connection: close\r\n
67.177.49.30:hu:10099: >> \r\n
67.177.49.30:hu:10099: sending data
67.177.49.30:hu:10099: EOF
67.177.49.30:fu:10099: EOF
NumOpen=0(0) NRead=0 Time=10

Any idea what this might be?

Perhaps the spammers have discovered port knocking?

Paul.

----------------------------------------------
This message was sent to the opt-in DSBL list.
If you do not want to receive DSBL messages,
please send mail to [email protected].