[Dshield] 4051/tcp

jayjwa jayjwa at atr2.ath.cx
Mon Jun 27 10:43:46 GMT 2005

I've been seeing alot of SYN packets to port 4051 lately. In fact, other 
than Qwest's on-going virus barrage (since June 7th) on 25 and the 
usual 445 stuff, it's the number one port getting attention in the 
firewall logs. The source ports are mid-high range and vary. A few (2-3) 
of the hosts I recognise. Sorted & uniq'ed, here's last night's hosts:

Of those, some had their 4051 filtered, some closed, and one was open. The 
open one wouldn't return any traffic when connected to. There didn't seem 
to be much on Google about it, just a few things about broken ftp 
connections which I doubt this is. Also a few mentions of a chat system 
I've never heard of. Has anyone seen activity on this port and might 
know what is going to & fro?

