[isapros] Re: Large number of dropped packets oon port 20100

  • From: "Jim Harrison" <Jim@xxxxxxxxxxxx>
  • To: <isapros@xxxxxxxxxxxxx>
  • Date: Fri, 7 Jul 2006 06:37:26 -0700

Have a nice read:
http://www.microsoft.com/technet/community/columns/sectip/st1205.mspx 

________________________________

From: isapros-bounce@xxxxxxxxxxxxx on behalf of Glenn P. JOHNSTON
Sent: Thu 7/6/2006 3:46 PM
To: isapros@xxxxxxxxxxxxx
Subject: [isapros] Large number of dropped packets oon port 20100




Hi,

One of the ISA2004 servers I look after has been logging a large number of 
dropped packet destined for port 20100,originating from various address in the 
60.100.x.x range, although if it is some kind of attack, this well may be 
spoofed. This started Wednesday evening Sydney time.

It's like 200 - 300 packets a minute being logged as dropped.

I've searched on the internet and can find no reference to anything like a 
virus / worm / DNS attack etc that uses port 20100, and it's only one of my 
clients, I've check my connection at home, and other clients, not even a wiff 
of the same thing. if was some kind of broad attack, i would expect to see it 
on more than just 1 client.

Anyone any clues on what this might be ?

Regards
Glenn




All mail to and from this domain is GFI-scanned.

Other related posts: