Re: Any tcp/608 activity?

From: Johannes Ullrich (jullrichat_private)
Date: Mon Sep 02 2002 - 11:11:53 PDT

  • Next message: Jeff Kell: "Strange back-orifice looking scan..."

    only very little activity on that port at DShield/ISC:
    
    http://isc.incidents.org/port_details.html?port=608
    
    
    On Sat, 31 Aug 2002 21:05:30 +0400
    "Andrey G. Sergeev (AKA Andris)" <andrisat_private> wrote:
    
    > Hello!
    > 
    > 
    > Did anyone here seen *any* activity, either legal or suspicious, on
    > TCP port 608 for, say, past 3 months? My question _isn't related_ to
    > Sender-Initiated/Unsolicited File Transfer proto (RFC 1440) although
    > I'm still interested in your comments if you're using this service and
    > have some records in the SIFT-UFT daemon logs saying something like
    > "Unrecognized command", "Invalid data", "Bad request" and so on.
    > 
    > Thanks.
    > 
    > 
    > -- 
    > 
    > Yours sincerely,
    > 
    > Andrey G. Sergeev (AKA Andris)
    > 
    > 
    > ------------------------------------------------------------------------
    > ---- This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management 
    > and tracking system please see: http://aris.securityfocus.com
    > 
    > 
    
    
    -- 
    --------------------------------------------------------------------
    jullrichat_private             Collaborative Intrusion Detection
                                             join http://www.dshield.org
    
    
    



    This archive was generated by hypermail 2b30 : Mon Sep 02 2002 - 11:16:52 PDT