[Dshield] Port 6101 Scans

David Taylor ltr at isc.upenn.edu
Sun Jun 26 22:05:19 GMT 2005


SANS is showing a sharp increase.  

http://isc.sans.org/port_details.php?port=6101&repax=1&tarax=2&srcax=2&perce
nt=N&days=10

Is this a worm?  I just now started seeing a large amount of different
source addresses hitting my tarpit for this port.  I was thinking it was a
bot network but maybe not.


==================================================
David Taylor //Sr. Information Security Specialist
University of Pennsylvania Information Security 
Philadelphia PA USA
LTR at ISC.UPENN.EDU               (215) 898-1236
http://www.upenn.edu/computing/security/
================================================== 

SANS - The Twenty Most Critical Internet Security Vulnerabilities 
http://www.sans.org/top20/

SANS - Internet Storm Center
http://isc.sans.org


-----Original Message-----
From: list-bounces at lists.dshield.org [mailto:list-bounces at lists.dshield.org]
On Behalf Of Jeff Kell
Sent: Sunday, June 26, 2005 5:52 PM
To: General DShield Discussion List
Subject: Re: [Dshield] Port 6101 Scans


David Taylor wrote:
> Anyone seeing an increase in port 6101 scanning?  I am wondering if a BOT
> network is hitting my subnet or if something else is going on.

It was #7 on my daily summary for Saturday (well, #4 excluding anomalies):

Port	Packets	Sources	Targets	Service	Name
6101	880	115	563	synchronet-rtc  	SynchroNet-rtc  

Jeff

_______________________________________________
send all posts to list at lists.dshield.org
To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list




More information about the list mailing list