Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: Port 1234 UDP traffic increase?

Subject: Re: Port 1234 UDP traffic increase?
Date: Fri, 14 Dec 2007 13:43:22 -0500
On Dec 14, 2007 12:05 PM, Bob Holowenko <holowenko@gmail.com> wrote:
Personally I do not think we have to worry about traffic from doubleclick.
They were bought out by Google last spring I believe. As for traffic on port
1234 I have not seen any increase in it. I will however be setting up some
packet sniffing on my network edge to see if I can get more information
about what is being carried in those packet.

Anyone have any wireshark caps already?


OK, I figured this one out with a little help from wireshark and the
machines receiving the traffic. Apparently 1234/UDP is used for a
proprietary Video Streaming application.

I think what I will take away from this is that while the last time I
was watching this much traffic, viruses were noisy and big. Today, the
ones to worry about are DDoS (80,53, 433, 8080, etc) and quiet C&C
channels. I guess the days of massive floods related to
malware/viruses/worms are long gone.

Once again, sorry for the noise. I will try and do some more legwork
before hitting up the list :-)

-JP

-------------------------------------------------------------------------
This list sponsored by: SPI Dynamics

ALERT: .How a Hacker Launches a SQL Injection Attack!.- White Paper 
It's as simple as placing additional SQL commands into a Web Form input box 
giving hackers complete access to all your backend systems! Firewalls and IDS 
will not stop such attacks because SQL Injections are NOT seen as intruders. 
Download this *FREE* white paper from SPI Dynamics for a complete guide to 
protection! 

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70160000000Cn8E
--------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>