Hello All,

This is perhaps off topic, but during easter our network firewall was
crashed by someone other than who it should have been.
Having rebuilt it, and turned on *lots* of packet filtering and logging,
have been amazed at the number of people who have been doing
a) port scanning,
b) attempting to telnet
c) sending packets continuously to ports with known vulnerabilites (even
though they are dropped), day after day.

The following networks were the source, and someone has tried to either
telnet to the firewall, or has been sending packets to ports with known
vulnerabilities, time and time again.  I have notified the admins at each of
the nets, but true to large corporate form (at least with the telcos) they
couldnt be bothered even answering.

attcanada.net
dc.com.pl
tin.it (telecom italia ?)
topshell.net (shonky looking isp selling shell access)
indosat.id

I know that chances are these were just stepping stones for the malevolent
person, but one thing that puzzles me:
some ips have host names like "x5-Pad14-ecde.attcanada.net" or
"ec-15ep.tin.it".
Are these system generated host names, or assigned to dialin lines during
connections, or ?

Maybe this is all par for the course, give up trying to let anyone know, and
I should just chalk it down to experience gathering? (this urks me as I know
someone had root access on one of these networks, which I presume means they
are compromised?)

</rant>

Top points for "progsoc.uts.edu.au", who read my vitriolic email, didnt
ignore me, and despite it are off looking for clues, all less than 12 hours
after notifying them of being port scanned from there, and sending them log
extracts.

Stu

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to