Use Discount Code SANSFIREISC10 when registering to get a 10% discount!!
Port 51616 - Got Packets?
Last Updated: 2013-05-19 14:06:38 UTC
by Kevin Shortt (Version: 1)
We're looking for any info or packets that target port 51616. After witnessing a spike yesterday on his network and checking that our port data [1] corroborated his event, Andrew has written in asking what we know.
The most useful snapshot of port activity can be seen in this graph image. I ran the graphs as far back as 2006 and nothing more signifcant was illustrated. The image below highlights yesterdays events as well as a more curious spike back in March. These counts do not seem very significant at first look, but they could clearly be telling us something.

So drop us a comment to share what you know. We're interested to attribute this traffic to something useful.
[1] https://isc.sans.edu/port.html?port=51616
If you have more information or corrections regarding our diary, please share.
Diary Archive
| Date | Author | Title |
|---|---|---|
| 2013-05-19 | Kevin Shortt | Port 51616 - Got Packets? (1 Comments) |
| 2013-05-17 | Daniel Wesemann | e-netprotections.su ? (3 Comments) |
| 2013-05-17 | Johannes Ullrich | SSL: Another reason not to ignore IPv6 (3 Comments) |
| 2013-05-16 | Joel Esler | Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability (1 Comments) |
| 2013-05-16 | Daniel Wesemann | Extracting signatures from Apple .apps (0 Comments) |
| 2013-05-15 | Joel Esler | Call for Papers - 4th annual Forensics and Incident Response Summit EU (0 Comments) |
| 2013-05-14 | Swa Frantzen | Firefox & Thunderbird released (0 Comments) |
| 2013-05-14 | Swa Frantzen | Adobe May 2013 Black Tuesday Overview (0 Comments) |
| 2013-05-14 | Swa Frantzen | Microsoft Security Advisory 2846338 (0 Comments) |
| 2013-05-14 | Swa Frantzen | CVE-2013-2094: Linux privilege escalation (0 Comments) |
| Search Diaries: | |

Complete Archive

