Results 1 to 10 of 10

Thread: UDP ports 15024 and 53

  1. #1
    Junior Member
    Join Date
    Oct 2003
    Posts
    4

    UDP ports 15024 and 53

    My firewall has logged about a hundred hits to 15024 and 53 starting around 2300 est, all from various hosts. What gives?

  2. #2
    Senior Member
    Join Date
    Oct 2002
    Posts
    1,130
    I was able to find this. It looks like an exploit designed to take advantage of vulnerabilities in BIND, BSD, and GNU versions of the DNS resolver. Just make sure that these are not normal DNS queries.

    I was unfortunately not able to find any references to port 15024.

    My suggestion would be to update your OS with the latest patch available.
    What OS are you running?
    Government is like fire - a handy servant, but a dangerous master - George Washington
    Government is not reason, it is not eloquence - it is force. - George Washington.

    Join the UnError community!

  3. #3
    Senior Member
    Join Date
    Jan 2003
    Posts
    220
    Just keep your firewall running
    [gloworange]And then it happened... a door opened to a world... rushing through the phone line like heroin through an addict\'s veins, an electronic pulse is sent out, a refuge from the day-to-day incompetencies is sought... a board is found. \"This is it... this is where I belong...\" I know everyone here... even if I\'ve never met them, never talked to them, may never hear from them again... I know you all...[/gloworange]

  4. #4
    DShield (http://www.dshield.org) reports lots of hits on 15024 on 9/11/03, not too much since.

  5. #5
    Junior Member
    Join Date
    Oct 2003
    Posts
    4
    I'm running Mac OSX with strict ipfw rules and blackhole enabled. I didn't consider the traffic a threat, I was more interested in what it could be.

  6. #6
    Junior Member
    Join Date
    Oct 2003
    Posts
    26
    UDP port 53 is for DNS, as for the 15024, most likely its an attempt for a game connection, found out that some games uses that particular port....

  7. #7
    AO's Fluffy Bunny cdkj's Avatar
    Join Date
    Feb 2003
    Posts
    1,236
    Also you might want to check out This
    I had to google 'jfgi' to see what it meant. The irony is overwhelming.

  8. #8
    T3h Ch3F
    Join Date
    Sep 2001
    Posts
    718

    Good advice

    Originally posted here by Limpster
    Just keep your firewall running

    This should be the end of the thread unless you are interested in those ports.





    BTW the guy has only just joined AO!!!!!!!!! Dont' neg him out yet!

    Do not scare good or potentially good ppl. away!

    Jezuz give the new members a chance!

    Have a fu(*ing heart!

    After all AO exixsts on ppl!

  9. #9
    Junior Member
    Join Date
    Oct 2003
    Posts
    4

    Re: Good advice

    Originally posted here by Galdron

    This should be the end of the thread unless you are interested in those ports.

    BTW the guy has only just joined AO!!!!!!!!! Dont' neg him out yet!
    The responses here haven't been off-putting, they've been helpful. My hope was that someone would recognize the activity.

  10. #10
    Junior Member
    Join Date
    Oct 2003
    Posts
    4

    Re: UDP ports 15024 and 53

    Originally posted here by rib0flavin
    My firewall has logged about a hundred hits to 15024 and 53 starting around 2300 est, all from various hosts. What gives?
    Answered my own question:

    Today I noticed another string of access attempts to (this time) udp port 11608 and 53. Then it occurred to me that I must be receiving packets meant for the previous owner of my dynamic IP. I confirmed in the firewall log that all the hits started after my modem had reconnected.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •