I don't know why, but yes, safety in numbers maybe?

----- Original Message -----
From: Matt Allen <[EMAIL PROTECTED]>
To: Stuart Hume <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Thursday, May 11, 2000 10:35 PM
Subject: Re: [SLUG] Annoyed with port scanners...


> Stuart,
>
> In my previous email i mentioned i have 2 colo's at Zip. They are being
> portscanned by the same machines as yours are(tin.it). We are running
> port Sentry (www.psionic.com). It drops the IPs from the route table and
> adds in an IPCHAINS rule realtime and reports them to /var/log/messages.
>
> I'd assume whoever is doing it is doing LARGE subnets (ie 61.8.*.*)
>
> I dont know if that puts your mind to rest at all.
>
> Matt
>
> Stuart Hume wrote:
> >
> > Hello All,
> >
> > This is perhaps off topic, but during easter our network firewall was
> > crashed by someone other than who it should have been.
> > Having rebuilt it, and turned on *lots* of packet filtering and logging,
> > have been amazed at the number of people who have been doing
> > a) port scanning,
> > b) attempting to telnet
> > c) sending packets continuously to ports with known vulnerabilites (even
> > though they are dropped), day after day.
> >
> > The following networks were the source, and someone has tried to either
> > telnet to the firewall, or has been sending packets to ports with known
> > vulnerabilities, time and time again.  I have notified the admins at
each of
> > the nets, but true to large corporate form (at least with the telcos)
they
> > couldnt be bothered even answering.
> >
> > attcanada.net
> > dc.com.pl
> > tin.it (telecom italia ?)
> > topshell.net (shonky looking isp selling shell access)
> > indosat.id
> >
> > I know that chances are these were just stepping stones for the
malevolent
> > person, but one thing that puzzles me:
> > some ips have host names like "x5-Pad14-ecde.attcanada.net" or
> > "ec-15ep.tin.it".
> > Are these system generated host names, or assigned to dialin lines
during
> > connections, or ?
> >
> > Maybe this is all par for the course, give up trying to let anyone know,
and
> > I should just chalk it down to experience gathering? (this urks me as I
know
> > someone had root access on one of these networks, which I presume means
they
> > are compromised?)
> >
> > </rant>
> >
> > Top points for "progsoc.uts.edu.au", who read my vitriolic email, didnt
> > ignore me, and despite it are off looking for clues, all less than 12
hours
> > after notifying them of being port scanned from there, and sending them
log
> > extracts.
> >
> > Stu
> >
> > --
> > SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> > To unsubscribe send email to [EMAIL PROTECTED] with
> > unsubscribe in the text
>
> --
> Matt Allen                                      Linux/PHP eCommerce
> Solutions
> Linux Worx                                      Linux Networking
> www.linuxworx.com.au                            Consulting
> [EMAIL PROTECTED]
> 0413 777 771
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to