[Dshield] Source port zero...

dougweb forum at dshield.org
Mon Nov 21 01:02:37 GMT 2005



In the last month or more I have had a rash of attacks using  source IP 0. These cannot be reported through DShield since the port number is below the port number value for reports. The other strange things about these is that virtually all of them show my IP as the only victim and each can have from 1 to five attempts. 

Are these spoofed IP's associated with port zero? The target port are the usual 1025 1026.  What might these be?

I'm also seeing attempts to reach the bootstrap port from 0.0.0.0.

I have a four PC home network for a small business and report to DShield just to do my part. Curious about what I'm seeing.
This message was sent via the web forum at
http://forum.dshield.org



More information about the list mailing list