2003004 : Suspicious TCP connection to FTP port

Low RiskLow Risk

Quick Links

Event description Jump to the top of this document

Most network accessible services are made available to client workstations by listening for clients on a well-known port. Most systems are only offering a limited number of the services at any time. Attackers often methodically probe the well-known service ports to determine what services are present on a system, looking for services that have known weaknesses that they can exploit. This activity is generally known as a "port sweep." In the process, an attacker will probe many ports, including those that are unused. Monitoring for access attempts against unused service ports points directly to this kind of activity.

Products that have this security check Jump to the top of this document

TCP_Probe_Ftp

This signature detects TCP port probes directed at port 21 (the FTP port).


Affected platforms Jump to the top of this document

How to remove this vulnerability Jump to the top of this document

Any instance of access attempts against unused services is worthy of investigation. On occasion these access attempts may be as simple as a user trying to telnet to a system that does not offer the telnet service. When there is a repeated attempt to access unused ports in a short time, this is almost certainly a port sweep and the actions of an attacker probing for vulnerabilities. Take immediate action to curtail this user's access to the system.

References Jump to the top of this document

Information about this document Jump to the top of this document

The information contained in this document may change without notice, and may have been altered or changed if you have received it from a source other than Internet Security Systems. Use of this information constitutes acceptance for use in an "AS IS" condition, without warranties of any kind, and any use of this information is at the user's own risk. Internet Security Systems disclaims all warranties, either expressed or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Internet Security Systems be liable for any damages whatsoever, including direct, indirect, incidental, consequential or special damages, arising from the use or dissemination hereof, even if Internet Security Systems has been advised of the possibility of such damages.

Copyright © 1997 – 2009 IBM Internet Security Systems. All rights reserved.

This page was created on Thu Jun 11 09:06:17 2009