Re: TCP Port


Subject: Re: TCP Port
From: Arthur Corliss (arthur@corlissfamily.org)
Date: Fri Jan 31 2003 - 14:51:53 AKST


On Fri, 31 Jan 2003, Adam Elkins wrote:

>
> This ip 24.247.194.57 is hitting my firewall MANY times....What odd, is the
> ports it trying to connect to...like this one; 31337
> Now, most of us know what 31337 means...anyone know of any trojans using this
> port?

Back Orifice is the most common backdoor that uses that port (using UDP,
anyway). They're probably just scanning for hosts that have common backdoors
installed. You'll probably see scans for 2140, 3150, 12345, and 12346 (UDP
for the first two, TCP for the latter) as well.

        --Arthur Corliss
          Bolverk's Lair -- http://arthur.corlissfamily.org/
          Digital Mages -- http://www.digitalmages.com/
          "Live Free or Die, the Only Way to Live" -- NH State Motto

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.



This archive was generated by hypermail 2a23 : Fri Jan 31 2003 - 15:22:01 AKST