PDA

View Full Version : [ubuntu] Port 17466: thousands of hits in last 24 h


DrJohn999
July 15th, 2009, 09:03 PM
My 8.04 LTS server, running Shorewall, logged over 10x the usual number of dropped packets yesterday, all directed at 17466 both tcp and udp, total number of dropped packets = 2384. Maybe that's not a lot in some places but here it's a new record.

These came from all sorts of source IP addresses ranging from 28.58.86.134 up to 222.228.125.206 with little or no apparent grouping. Source ports are variable. Timestamps from Jul 14 21:56:07 to Jul 15 04:30:39

Anyone else see this? I'm curious about this sudden change in firewall bashing patterns / quantity.

-- Dr J.

aesis05401
July 15th, 2009, 09:13 PM
I'm not seeing this activity in my netblock, but I checked the IANA reg and there isn't anything official assigned to that port number.

Probably somone has an exploit in the wild listening on that port and they are scanning your netblock for zombies.

I should mention I get constant scanning of the sort you mention, just not that port recently.

The Cog
July 16th, 2009, 05:32 PM
My advice is to stop logging dropped packets. Dropped packets can't harm you - they've been dropped. The ones that harm you are the ones that get through, and of course they don't get logged.

bodhi.zazen
July 16th, 2009, 05:40 PM
My advice is to stop logging dropped packets. Dropped packets can't harm you - they've been dropped. The ones that harm you are the ones that get through, and of course they don't get logged.

The internet is a scary place. Nothing like reading the logs to encourage a bit of security. Try opening port 22 :lolflag:

That level of traffic is nothing to be concerned with, IMO, and the packets were dropped.