Re: increase of scans against port 1524

From: Joe Matusiewicz (joemat_private)
Date: Wed Jun 05 2002 - 09:39:43 PDT

  • Next message: Antonio Stano: "Strange IIS Pattern..."

    At 07:17 AM 6/5/02, High Speed wrote:
    >Hi,
    >
    >last 2 days I noticed an increased scan against port 1524
    >
    >ingreslock      1524/tcp    ingres
    >ingreslock      1524/udp    ingres
    >
    >Are there known issues with this port ?
    >Recently found vulnerabilities ?
    
    I remember that being a backdoor port for a whole bunch of different buffer 
    overflow attacks.  A google search on "port 1524" will cough up some names 
    for you.  It could be scans of random addresses by vultures looking for 
    compromised boxes with convenient backdoors.  In our case, one of solaris 
    boxes was compromised eighteen months ago and someone bragged on IRC that 
    they placed a backdoor on this port but never mentioned which of our boxes 
    was compromised.  Our networks were scanned heavily on this port and this 
    got our attention.  When we did our own scanning we discovered which of our 
    boxes was r00ted.
    
    -- Joe 
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Jun 05 2002 - 10:01:33 PDT