Re: many port 4599 probes

From: Mike Tancsa (mikeat_private)
Date: Thu Oct 18 2001 - 19:36:11 PDT

  • Next message: VanMeter, John: "Has anyone seen this pattern?"

    HylaFax makes use of this port.
    
             ---Mike
    
    At 11:29 PM 10/18/2001 +0100, Alan Wright wrote:
    >4599 is an unassigned port according to the IANA ports list.
    >
    >At 19:59 17/10/2001 +0545, you wrote:
    >>My ipchains log shows that I received 85 attempted udp connections to port
    >>4599 in just over 3 minutes, apparently from a host calling itself
    >>shtam017085.netvigator.com (208.139.101.85).
    >>
    >>The attempted connections came regularly every two seconds from
    >>208.139.101.85:4599 -> my_address:4599
    >>
    >>ipchains is set to DENY rather than REJECT, perhaps accounting for the delay
    >>between attempts.
    >>
    >>Does anyone have any idea what this might be/mean?
    >>
    >>Thanks for any help
    >>
    >>CP
    >>
    >>
    >>----------------------------------------------------------------------------
    >>This list is provided by the SecurityFocus ARIS analyzer service.
    >>For more information on this free incident handling, management
    >>and tracking system please see: http://aris.securityfocus.com
    >
    >All the best
    >
    >Alan
    >
    >
    >
    >Alan J Wright B.Sc(Hons)(Open)
    >SMS +47624462772.
    >Email AlanJWrightat_private
    >         foll478trapat_private
    >
    >
    >'You're a feisty little one but you'll soon learn respect'
    >
    >Return of the Jedi
    >
    >
    >----------------------------------------------------------------------------
    >This list is provided by the SecurityFocus ARIS analyzer service.
    >For more information on this free incident handling, management and 
    >tracking system please see: http://aris.securityfocus.com
    >
    
    --------------------------------------------------------------------
    Mike Tancsa,                          	          tel +1 519 651 3400
    Sentex Communications,     			  mikeat_private
    Providing Internet since 1994                    www.sentex.net
    Cambridge, Ontario Canada			  www.sentex.net/mike
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Oct 18 2001 - 19:44:12 PDT