[Dshield] Excessive amount of UDP port 10254 probes
gravyface at bmfsquad.com
Sun Nov 17 04:10:30 GMT 2002
Over the last 24hrs, I'm experienced a large amount of UDP port probes directed at port 10254 but originating from many different ports and many different hosts.
One of the sources of the attack is currently number 10 on the Top Ten list (p5082F21D.dip.t-dialin.net), however, at least a dozen others have attempted the same attack on the same port. All attempts have failed, however, my software firewall (Black Ice Defender) is spiking cpu usage to over 30%.
In total, I've probably received over 4000 UDP port 10254 probes during the last 24 hours. This is a home win2k desktop machine not running any server applications.
Is anyone familiar with port 10254?
Thanks in advance
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the list