[Current] Re: Port 2605 from few IPs

jayjwa jayjwa at atr2.ath.cx
Tue Jun 15 23:53:46 UTC 2004

On Tue, 15 Jun 2004 Jonathan C. Webster wrote:

+ From: "Jonathan C. Webster" <jwebster03 at snet.net>
+ Subject: [Current] Port 2605 from few IPs
+ To: current at lists.dshield.org
+ Message-ID: <40CE12EB.5010904 at snet.net>
+ Content-Type: text/plain; charset=us-ascii; format=flowed

+ Are other folks seeing a lot of probes to port 2605 from only a few hosts?

I hadn't noticed any here, but about once per day I'll get requests to 
some strange port, similar to this (although I doubt they are related). 
What do the packets look like (hex)? Just SYN's? Or something more? Do 
they hit other ports during the same 'run', or all probes are going to 
that one port?

--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++

