My perception is that the volume of scanning has in fact decreased in the
past week or so; probably the calm before the storm.  I have had a lot of
scans from Oz addresses, but in most cases they are compromised Linux
boxes running old versions of Redhat with no security considerations.

Howard.
______________________________________________________
LANNet Computing Associates <http://www.lannet.com.au>

On Mon, 10 Apr 2000, John Clarke wrote:

> On Mon, Apr 10, 2000 at 12:09:52PM +1000, [EMAIL PROTECTED] wrote:
> 
> > My sites are being hit by a constant barrage of packets for port 137 - all
> > of which are being blocked by the firewall, but the number of them is
> > disconcerting.
> 
> I see these regularly (although I wouldn't describe it as a constant
> barrage).  Always udp, and always from port 137 to port 137. I don't
> believe, as Charlie suggested, it's an innocent netbios name lookup,
> because our entire subnet is scanned at once.  More likely it's someone
> looking for an easy target.
> 
> Other scans I see regularly are against port 111 (portmapper), 31789 (back
> orifice), 98 (linuxconf), 2140 (a windows trojan) and 1243 (another
> windows trojan, I believe), with occasional scans for standard servers
> such as ftp, dns and web.
> 
> If you're permanently connected to the net, expect to be scanned several
> times each week, and take appropriate precautions.  Many scans originate
> in Korea or Brazil, most of the rest are from the US.  Only a few have
> originated in Australia.
> 
> 
> Cheers,
> 
> John
> -- 
> whois [EMAIL PROTECTED]
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to