RE: Probes to strange ports

From: Kinsey, Robert (Robert.Kinseyat_private)
Date: Wed Mar 06 2002 - 16:24:09 PST

  • Next message: H C: "RE: Probes to strange ports"

    Kenneth,
    
    Same results looking for those ports.  Can you explain the activity a little
    further?
    
    What KIND of traffic are you seeing on these ports?  Are they to one
    particular system?  If so, have you run any analysis tools on it (i.e.
    TDImon, or FileMon, etc...)?
    
    Is there any kind of consistency to the packets?  Are they all TCP or is
    there UDP as well?  Is it at a certain time?  What kind of systems are you
    seeing the activity on?  OS?  versions?  Apps involved (if identified)?
    
    Rob
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Mar 06 2002 - 16:46:49 PST