[lug] port 1433

Rob Riggs rob at pangalactic.org
Wed Oct 16 14:07:54 MDT 2002


Sorry folks... reading very old mail due to mis-sorting my mailbox.

Rob Riggs wrote:

> Well, since I'm seeing the same thing on my firewall, I'm guessing 
> there's a new scanning tool out there that the script-kiddies are 
> using to look for a vulnerable service on 1433.
>
> BTW, my /etc/services says:
>
> ms-sql-s    1433/tcp            # Microsoft-SQL-Server
> ms-sql-s    1433/udp            # Microsoft-SQL-Server
>
> CERT just put out their top 10 vulnerabilites list and SQL-Server was 
> #3 on the Microsoft list, IIRC.
>
> j davis wrote:
>
>> Hello,
>>  for the last few months i have been getting tcp request from the 
>> internet
>> to port 1433...mysql. I dont have any sql servers running on the box 
>> in question..
>> is this a scan for a exploit...or is this just a box spewing out 
>> random crap.
>>
>> Aug 13 03:56:54 www kernel: IPT INT>FIRE:IN=eth0 OUT=
>> MAC=00:01:02:8f:de:db:00:30:85:e5:b7:64:08:00 SRC=211.244.220.87 
>> DST=10.0.0.2 LEN=48
>> TOS=0x00 PREC=0x00 TTL=106 ID=28391 DF PROTO=TCP SPT=1551 DPT=1433 
>> WINDOW=16384
>> RES=0x00 SYN URGP=0
>
>
>
>
>
> _______________________________________________
> Web Page:  http://lug.boulder.co.us
> Mailing List: http://lists.lug.boulder.co.us/mailman/listinfo/lug
> Join us on IRC: lug.boulder.co.us port=6667 channel=#colug







More information about the LUG mailing list