Handler on Duty: Didier Stevens
Threat Level: green
Loading...
|
|
Submitted By | Date |
---|---|
Comment | |
Mikael Olsson | 2009-10-04 18:45:22 |
Port 999, TCP as well as UDP, is also used for remote administration of Clavister Firewall (www.clavister.com). Recurring UDP 999 "probes" can mean that someone mistyped the address of a firewall in the management tool, which periodically (app. once a minute) "pings" all firewalls it knows about. High volumes of UDP 999 packets can also mean that a firewall was configured to send log data to the wrong IP address. (Perhaps a less likely mistake to make.) TCP traffic related to this is least likely to occur "frequently"; it will only occur when someone is manually trying to do something in the admin tool. Note that traffic related to Clavister Firewall management would be targeted against a single (or a few) IP addresses. Scan sweeps for port 999 covering several addresses would NOT be related to the above. Addresses like 1.2.3.4 and such are however known to be frequent targets of UDP 999 probes from multiple sources :) | |
2003-02-21 02:58:12 | |
This port is also used by Microsoft ActiveSync and Pocket PC devices. |
CVE # | Description |
---|