Stuart,

In my previous email i mentioned i have 2 colo's at Zip. They are being
portscanned by the same machines as yours are(tin.it). We are running
port Sentry (www.psionic.com). It drops the IPs from the route table and
adds in an IPCHAINS rule realtime and reports them to /var/log/messages.

I'd assume whoever is doing it is doing LARGE subnets (ie 61.8.*.*)

I dont know if that puts your mind to rest at all.

Matt

Stuart Hume wrote:
> 
> Hello All,
> 
> This is perhaps off topic, but during easter our network firewall was
> crashed by someone other than who it should have been.
> Having rebuilt it, and turned on *lots* of packet filtering and logging,
> have been amazed at the number of people who have been doing
> a) port scanning,
> b) attempting to telnet
> c) sending packets continuously to ports with known vulnerabilites (even
> though they are dropped), day after day.
> 
> The following networks were the source, and someone has tried to either
> telnet to the firewall, or has been sending packets to ports with known
> vulnerabilities, time and time again.  I have notified the admins at each of
> the nets, but true to large corporate form (at least with the telcos) they
> couldnt be bothered even answering.
> 
> attcanada.net
> dc.com.pl
> tin.it (telecom italia ?)
> topshell.net (shonky looking isp selling shell access)
> indosat.id
> 
> I know that chances are these were just stepping stones for the malevolent
> person, but one thing that puzzles me:
> some ips have host names like "x5-Pad14-ecde.attcanada.net" or
> "ec-15ep.tin.it".
> Are these system generated host names, or assigned to dialin lines during
> connections, or ?
> 
> Maybe this is all par for the course, give up trying to let anyone know, and
> I should just chalk it down to experience gathering? (this urks me as I know
> someone had root access on one of these networks, which I presume means they
> are compromised?)
> 
> </rant>
> 
> Top points for "progsoc.uts.edu.au", who read my vitriolic email, didnt
> ignore me, and despite it are off looking for clues, all less than 12 hours
> after notifying them of being port scanned from there, and sending them log
> extracts.
> 
> Stu
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text

-- 
Matt Allen                                      Linux/PHP eCommerce
Solutions
Linux Worx                                      Linux Networking
www.linuxworx.com.au                            Consulting
[EMAIL PROTECTED]                           
0413 777 771
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to