Hosts sending 2 or 6 NULL bytes #net

🕤︎ - 2019-08-16

Recently, like the last month or so, my server has been receiving packets from various, seemingly arbitrary, hosts, containing either 2 or 6 NULL bytes.

They hit mostly port 22 (ssh), 53 (dns), 80 (http), 443 (https) and imaps (993). I only have a very limited number of ports open in the router, so they might be hitting more ports.

Looking at them with ngrep(8), it looks like this:

$ sudo ngrep -x -q '^\x00\x00*$'
interface: enp4s0 (
filter: ((ip || ip6) || (vlan && (ip || ip6)))
match: ^\x00\x00*$
T -> [S] #32
  00 00                                                 ..
T -> [S] #41
  00 00                                                 ..
T -> [S] #46
  00 00                                                 ..
T -> [S] #62
  00 00                                                 ..
T -> [R] #404
  00 00 00 00 00 00                                     ......

I'm not quite sure to make of it. The sources seem to change, sometimes they're mostly from Japan, sometimes from China, sometimes from AWS, other times from various hosting companies.

Anyone know what this is?

