Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Incidents
Packet from port 80 with spoofed microsoft.com ip Jan 29 2003 10:46AM
Michael Rowe (mrowe mojain com) (4 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 03:31AM
Keith Owens (kaos ocs com au) (2 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 06:10PM
dr john halewood (john frumious unidec co uk)
Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Jan 30 2003 06:03PM
Tomasz Papszun (tomek-incid lodz tpsa pl) (5 replies)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Jan 31 2003 07:21PM
Chris (christian ritter noc homeunix org)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Jan 31 2003 02:01AM
Peter Triller (ptriller xebec de) (2 replies)
Re: Packets from 255.255.255.255(80) Feb 02 2003 08:27PM
Guy Reisenauer (greisen mail prosser wsu edu)

I saw these packets as well, 814 of them over a 24 hour period starting
on the 29th. The inbound ACL on the Cisco stopped them.

Jan 30 11:27:36 cahe-prosser 4951: 1w6d: %SEC-6-IPACCESSLOGP: list 165
denied tcp 255.255.255.255(80) -> aaa.www.xxx.yyy(27127), 1 packet

You are right that they do not make sense. They hit the entire range of
IP's in a fairly random order and random ports. The old smurf style
attacks used to take this form but targeted specific ports such as 19.

Guy

On Fri, 31 Jan 2003, Peter Triller wrote:

> >I am seeing a lot of sync/ack packets from port 80 to non-existent
> >addresses on my networks. Somebody is spoofing source addresses to
> >attack hosts, we are just innocent victims. When will ISPs learn that
> >they should filter their customer's packets to prevent spoofing? I am
> > even seeing syn/ack packets from 255.255.255.255:80!
>
> I cant see much reason in such packets, since they wont give any feedback.
> sport 80 is obviously to bypass some firewalls.
> But if he doesnt get feedback only 2 reasons pop into mind:
> - an attack similar to the worm , but the random ports don't make sense then
> - a very badly configured and/or broken piece of software/hadware.
>
>
>
> Peter
>
>
> ------------------------------------------------------------------------
----
> This list is provided by the SecurityFocus ARIS analyzer service.
> For more information on this free incident handling, management
> and tracking system please see: http://aris.securityfocus.com
>

------------------------------------------------------------------------
----
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com

[ reply ]
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Jan 31 2003 08:11PM
Tomasz Papszun (tomek-incid lodz tpsa pl) (1 replies)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Feb 02 2003 05:33PM
Hugo van der Kooij (hvdkooij vanderkooij org) (1 replies)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Feb 03 2003 03:56PM
Frederic Harster (f harster evc net) (2 replies)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Feb 04 2003 06:46PM
Christian Vogel (chris obelix hedonism cx) (1 replies)
Re: Packets from 255.255.255.255(80) (was: Packet from port 80 withspoofed microsoft.com ip) Jan 30 2003 11:45PM
Russell Fulton (r fulton auckland ac nz)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 29 2003 08:01PM
H C (keydet89 yahoo com) (1 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 11:19AM
Michael Rowe (mrowe mojain com) (1 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 07:34PM
Kurt Seifried (bt seifried org)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 29 2003 05:12PM
Thiago Conde Figueiró (thiago figueiro ciphertech com br) (2 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 05:20PM
Rich Puhek (rpuhek etnsystems com)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 04:14AM
Valdis Kletnieks vt edu
Re: Packet from port 80 with spoofed microsoft.com ip Jan 29 2003 05:06PM
Chris Wilkes (cwilkes ladro com) (1 replies)
Re: Packet from port 80 with spoofed microsoft.com ip Jan 30 2003 11:16AM
Michael Rowe (mrowe mojain com)







 

Privacy Statement
Copyright 2009, SecurityFocus