On Mon, Apr 10, 2000 at 12:09:52PM +1000, [EMAIL PROTECTED] wrote:

> My sites are being hit by a constant barrage of packets for port 137 - all
> of which are being blocked by the firewall, but the number of them is
> disconcerting.

I see these regularly (although I wouldn't describe it as a constant
barrage).  Always udp, and always from port 137 to port 137. I don't
believe, as Charlie suggested, it's an innocent netbios name lookup,
because our entire subnet is scanned at once.  More likely it's someone
looking for an easy target.

Other scans I see regularly are against port 111 (portmapper), 31789 (back
orifice), 98 (linuxconf), 2140 (a windows trojan) and 1243 (another
windows trojan, I believe), with occasional scans for standard servers
such as ftp, dns and web.

If you're permanently connected to the net, expect to be scanned several
times each week, and take appropriate precautions.  Many scans originate
in Korea or Brazil, most of the rest are from the US.  Only a few have
originated in Australia.


Cheers,

John
-- 
whois [EMAIL PROTECTED]
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to