[lug] port 1433

Rob Riggs rob at pangalactic.org
Wed Oct 16 14:03:59 MDT 2002

Well, since I'm seeing the same thing on my firewall, I'm guessing 
there's a new scanning tool out there that the script-kiddies are using 
to look for a vulnerable service on 1433.

BTW, my /etc/services says:

ms-sql-s    1433/tcp            # Microsoft-SQL-Server
ms-sql-s    1433/udp            # Microsoft-SQL-Server

CERT just put out their top 10 vulnerabilites list and SQL-Server was #3 
on the Microsoft list, IIRC.

j davis wrote:

> Hello,
>  for the last few months i have been getting tcp request from the 
> internet
> to port 1433...mysql. I dont have any sql servers running on the box 
> in question..
> is this a scan for a exploit...or is this just a box spewing out 
> random crap.
> Aug 13 03:56:54 www kernel: IPT INT>FIRE:IN=eth0 OUT=
> MAC=00:01:02:8f:de:db:00:30:85:e5:b7:64:08:00 SRC= 
> DST= LEN=48
> TOS=0x00 PREC=0x00 TTL=106 ID=28391 DF PROTO=TCP SPT=1551 DPT=1433 
> WINDOW=16384
> RES=0x00 SYN URGP=0

