Code:
FWOUT 4/14/2009 22:37:18 -4:00 GMT 192.168.2.100:[COLOR="Red"]1645 [/COLOR]192.168.2.102:[COLOR="Blue"]139[/COLOR] TCP (flags:S)
this is an outbound request on port 1645 to the remote filesharing port 139
Usually this is FROM port 139 to 139 or a broadcast on address 192.168.2.225:139
[edit] WRONG!
>>> so the use of port 1645 is suspicious <<<
see below for explanation
[/edit]
lookup the ZA meaning of TCP (flags:S)
the remainder are some form of
Code:
FWIN 4/14/2009 22:58:08 -4:00 GMT 94.183.113.171:[COLOR="Blue"]xxxx[/COLOR] 192.168.2.100:[COLOR="Red"]34917[/COLOR] TCP (flags:S)
or
FWIN 4/14/2009 22:17:12 -4:00 GMT 222.167.4.165:18078 192.168.2.100:[COLOR="Red"]34917[/COLOR] UDP
Looking on the Cisco site I found
Sensor6x# show events alert | include id=5854
evIdsAlert: eventId=1166761098236251265 severity=medium vendor=Cisco
originator:
hostId: R4-IPS4240a
appName: sensorApp
appInstanceId: 380
time: 2007/04/11 05:15:33 2007/04/11 00:15:33 CDT
signature: description=Cisco CUCM/CUPS Denial of Service Vulnerability
id=5854 version=S279
subsigId: 1
sigDetails: SCCP Port Scan Denial of Service Vulnerability
marsCategory: DoS/MiscServer
interfaceGroup: vs0
vlan: 0
participants:
attacker:
addr: locality=OUT 192.168.208.63
port: 34917
target:
addr: locality=OUT 192.168.132.44
port: 2000
os: idSource=unknown relevance=relevant type=unknown
context:
fromAttacker: