|
|||||||||||
|
Re: Logs: Many hits with source port of 80
From: Joe Stewart <jstewart(at)lurhq.com>
Date: Mon Dec 16 2002 - 10:27:32 EST
On Friday 13 December 2002 05:05 am, Byrne Ghavalas wrote:
Hi, Whenever I get a source-port-80-to-high-port scan I suspect network misconfiguration/lost state connection on the firewall. (Never attribute to malice that which can be adequately explained by stupidity) An easy way to check is telnet to port 80 on the source host. In this case:
[test@test test]$ telnet 194.78.225.36 80
Trying 194.78.225.36...
The requested URL, "http://194.78.225.36:8808/", cannot be accessed using your current browser.<P> </BODY></HTML> Connection closed by foreign host. Hmm. "Footprint Distributor V2.0". Sounds like a load balancer. Some Googling turns up a product called "Footprint" from a company called Sandpiper that does distributed content caching. Lets see if they actually use the product to serve their own website:
[test@test test]$ telnet www.sandpiper.net 80
Trying 63.208.96.131...
Suspicion confirmed. My guess is that the probes you are getting are reply SYN-ACK packets from a webserver you are trying to visit. They have somehow misconfigured the load balancer and the replies are coming from the wrong IP address, so your firewall sees them as an entirely different connection and drops the packets. -Joe -- Joe StewartReceived on Mon Dec 16 13:11:52 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:54 EDT |
||||||||||
|
|||||||||||