Port 17889 - new attack?

From: James Willmore (jwillmoreat_private)
Date: Mon Oct 08 2001 - 22:51:08 PDT

  • Next message: Miller, Toby: "RE: new pop3 exploit out?"

    This is an email sent to me by SWATCH.  I've gotton quite a few of these packets from various sources.  What is this??  Although I have dropped the packet, I wonder what this is.
    
    Any ideas, thoughts, answers are welcomed.
    
    Thanks.
    
    Begin forwarded message:
    
    Date: Tue, 9 Oct 2001 01:34:22 -0400
    From: root <root@xxxx>
    To: root@xxxx
    Subject: 'SWATCH - Droped packet'
    
    
    Oct  9 01:34:15 xxxx kernel: Shorewall:net2all:DROP:IN=ppp0 OUT= MAC= SRC=172.180.19.4 DST=x.x.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=63493 DF PROTO=TCP SPT=21027 DPT=17889 WINDOW=8192 RES=0x00 SYN URGP=0 
    
    
    -- 
    Jim Willmore
    jwillmoreat_private
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Oct 09 2001 - 08:25:39 PDT