My router/firewall has been dropping a lot of packets lately from miscellaneous sources. Recently i have found some that have interested me a lot, these packets from source port 666 and destination port 1026. All have been dropped by the firewall, but should i STILL be worried? What does this mean? I have broadband internet. Anyone have any good resources to find information about certain ports and internet traffic?
Thank you, ZeKe
This conversation is currently closed to new comments.
I believe that source port 666 is used by the game Doom, but it is also commonly used by backdoor and trojan programs. Port 1026 is now commonly being used for WMS Spamming, since many ISP's are still blocking port 135 (due to MS Blaster worm).
A good list of ports and their associated applications can be found here: http://www.commodon.com/threat/threat-allports.htm Just remember that these are only the most "common" user's of the ports, but other application can use them also.
You can also find good information on port traffic at the Internet Storm Center, http://isc.sans.org
If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.
port 666?
Thank you,
ZeKe