You are not logged in.

#1 2010-12-29 22:02:50

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,237
Website

UDP Port 18273

Does anyone have any idea what UDP port 18273 is? I'm seeing an unusually large amount of blocks on my firewall for this. I find it strange for several reasons:
1) It's UDP 18273.
2) There's over 2000 blocks for it already this week.
3) It's from all over the world, not just one source.

Just this week:

      3 SRC=109.110.83.26
      3 SRC=109.89.12.169
      3 SRC=156.26.118.151
      3 SRC=193.136.129.191
    174 SRC=213.88.78.9
     66 SRC=2.36.48.163
      3 SRC=41.121.28.166
    117 SRC=78.134.48.165
    218 SRC=79.16.16.15
     18 SRC=79.25.116.103
      9 SRC=79.27.13.120
      3 SRC=79.55.85.213
      3 SRC=80.181.72.49
    188 SRC=80.68.181.94
      3 SRC=80.86.125.14
      3 SRC=81.165.118.247
    166 SRC=82.56.62.209
     34 SRC=83.211.66.28
      9 SRC=85.230.4.24
    337 SRC=87.1.123.171
     99 SRC=87.1.231.85
    299 SRC=87.19.62.228
      3 SRC=87.4.233.216
     33 SRC=87.8.95.129
     11 SRC=93.145.209.241
    202 SRC=93.146.150.147

I've got a traffic capture running now to try and see what's going on, just wondering if anyone else is seeing anything similar.

Offline

#2 2010-12-29 22:17:58

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,237
Website

Re: UDP Port 18273

Capture if anyone wants a closer look... Nothing stands out as an explanation:
http://ompldr.org/vNnJ5Zw/udp18273.pcap

Offline

#3 2010-12-30 10:02:38

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: UDP Port 18273

huh. no clue.

Are all the source ports the same too? In the pcap they were.
From those caps, it is hard to tell if it was response packets from outbound connection attempts that NAT rules had simply expired on, or inbound traffic.

src: 7513/udp
dst: 18273/udp

iana port allocations list says:

#               7512-7541   Unassigned
#               18263-18462 Unassigned

If you do reverse lookups on those IP addresses, you get..

59.167.180.125 - mail.naturesorganics.com.au -- apnic ip block owner -- http://whois.arin.net/rest/nets;q=59.16 … ARIN=false

87.4.233.216 - host216-233-dynamic.4-87-r.retail.telecomitalia.it. -- ripe ip block owner info -- http://www.db.ripe.net/whois?form_type= … rch=Search


So you have one ip that is a mailserver (in what appears to be melborne AU) and one that is some isp end user (in italy. Udine?).

I guess it depends on which IP is yours. tongue
If you run the mailserver, I would suggest you look for anything bound to unexpected ports, and maybe do a rootkit check run or something. If nothing untorward shows up, just keep an eye on the logs looking for anything else unusual.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#4 2010-12-30 12:27:31

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,237
Website

Re: UDP Port 18273

The 59. address is ours. It's a CentOS box acting as a primary firewall. There's an additional /29 behind the firewall, but all outbound is SNAT'ed to the 59. address above. Nothing seems untoward outbound as best I can tell. I'll have to have another look tomorrow.

That's just one example of an inbound connection attempt that I grabbed this morning after reviewing the daily logs.

We've been having a discussion on the SANS group about it, but no conclusion made:
http://groups.google.com/group/iscdshie … 941d092764

Offline

#5 2010-12-30 20:30:43

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: UDP Port 18273

Yeah. hmm.

I guess I would try a capture on the egress FW box with src= 18273/udp just to see if this is return data from some outbound naughty service (pwned box or control box for some botnet), or if it is indeed all inbound connection attempts.

keep us (me) posted though. very interesting.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#6 2010-12-30 22:38:31

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,237
Website

Re: UDP Port 18273

cactus wrote:

I guess I would try a capture on the egress FW box with src= 18273/udp just to see if this is return data from some outbound naughty service (pwned box or control box for some botnet), or if it is indeed all inbound connection attempts.

Nothing on that port... Trying to get a pcap of all traffic to/from a specific host to see what (if any) other ports are talking to it. I think I might be chasing my tail though sad

Will let you know if I find anything smile

(OT: NYE Tacos tonight big_smile tongue)

Offline

#7 2010-12-31 07:09:23

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: UDP Port 18273

wooo tacos!
big_smile


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

Board footer

Powered by FluxBB