Re: TCP Port


Subject: Re: TCP Port
From: Adam Elkins (i-robot@gci.net)
Date: Fri Jan 31 2003 - 15:27:24 AKST


I wonder if the guy knows he has all those ports listening on his box? Thats
kinda funny.

Adam

On Friday 31 January 2003 02:51 pm, Arthur Corliss wrote:
> On Fri, 31 Jan 2003, Adam Elkins wrote:
> > This ip 24.247.194.57 is hitting my firewall MANY times....What odd, is
> > the ports it trying to connect to...like this one; 31337
> > Now, most of us know what 31337 means...anyone know of any trojans using
> > this port?
>
> Back Orifice is the most common backdoor that uses that port (using UDP,
> anyway). They're probably just scanning for hosts that have common
> backdoors installed. You'll probably see scans for 2140, 3150, 12345, and
> 12346 (UDP for the first two, TCP for the latter) as well.
>
> --Arthur Corliss
> Bolverk's Lair -- http://arthur.corlissfamily.org/
> Digital Mages -- http://www.digitalmages.com/
> "Live Free or Die, the Only Way to Live" -- NH State Motto
>
>
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.



This archive was generated by hypermail 2a23 : Fri Jan 31 2003 - 15:43:20 AKST