Router log shows port 1026 activity?

May 08, 2006 3 Replies

My router logs are showing a lot of messages similar to the following:



ICMP: Dest Unreachable Port Unreachable, LOCAL source XX.xx.xxx.xxx:2502 (UDP), original dest 64.108.188.246:1026



Where the Xs are my IP address. As I understand it, port 1026 is the Windows Messenger port and is the subject of a lot of pop-up spam. I run virus protection on all my computers and can't find any trojans or bots on my computers.



I am probably getting about 2-3 of these messages a minute logged on my router. Do I need to be worried about them? As I understand it, it is easy to spoof a local source address. I am assuming that someone has spoofed my address and I am just getting a bounce-back error message. Is this correct?



FYI, according to DShield, another IP address that I "own" is getting logged as sending out these requests. I don't even have that IP address hooked up to a computer, so again I am assuming a spoofed source address. Am I correct?



Thanks, Jay


Or a randomly assigned unprivilegded port. Hardly interesting.

Well, that's way more interesting. Do you have any capture of sniffed network traffic?

I don't have a sniffer. Any suggestions for a cheap/free sniffer for a Micro$oft system?

I'm not worried about the port 2502 in the source. Again, I understand that is a random number. It is just that ALL the log lines end with port 1026. I'm hoping the spammer just spoofed my IP for the source and I am only catching the error message that was bounced back.

A further note, I don't have port 1026 pinholed in my router, so no one can get in that way.

Thanks, Jay

WinPCap + Ethereal

Oh, ALL? Now that makes it clearer.

You should assume that some RPC service running locally on your machine makes those requests.

Except when the session is initiated from the inside.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required