So, yesterday I started running a new service on an external "sniffer". It picks up on SYN's only.... Looking at the log I today I see _lots_ of SYNs from a single IP..... So I take a look around.... Interesting.... The firewall reports a single machine making outbound requests on port 80 between 1 and 4 times per minute for a minute, then waiting and seemingly random time and trying again.... The interesting thing is that immediately after the outbound port 80 request to the remote IP the remote IP tries an inbound SYN on a high port that is blocked by the firewall. The local and remote complete the three-way and then the remote attempts the inbound..... After an undeterminable amount of time, (I haven't had time to look.... :( ), the inbound attempted port changes. But it only started at 16:09 local and I started the service 3 hours before....
Unfortunately, I don't control the computer that is doing this.... So I called the admin and asked for domain admin username/password and local admin/password combinations.... Got both and neither work! A tad worrying....
I have blocked the remote at the firewall, told the admin to relax and get drunk for the weekend and I'll call her on monday...... Not to mess with the machine, disconnect it or turn it off.....
So... The question is.... Is there something on that machine that is contacting, through an unblockable port, a machine that will then test the firewall rules back trying to find a hole..... It looks like it to me..... But I might just be being a moron...... :eek:
Anyone have any experirnce with this or is it simple spyware?
