Hello all...
I noticed the following today:
Jun 7 13:27:01 www-cache.lshtm.ac.uk snort[632]: spp_portscan:
PORTSCAN DETECTE
D from 206.251.0.173
Jun 7 13:27:14 www-cache.lshtm.ac.uk snort[632]: spp_portscan: portscan status
from 206.251.0.173: 1 connections across 1 hosts: TCP(1), UDP(0) STEALTH
Jun 7 13:27:19 www-cache.lshtm.ac.uk snort[632]: spp_portscan: End of portscan
from 206.251.0.173
Jun 7 13:30:52 www-cache.lshtm.ac.uk snort[632]: spp_portscan:
PORTSCAN DETECTE
D from 206.251.0.173
Jun 7 13:30:58 www-cache.lshtm.ac.uk snort[632]: spp_portscan: portscan status
from 206.251.0.173: 1 connections across 1 hosts: TCP(1), UDP(0) STEALTH
Jun 7 13:31:04 www-cache.lshtm.ac.uk snort[632]: spp_portscan: End of portscan
from 206.251.0.173
Jun 7 13:32:52 www-cache.lshtm.ac.uk snort[632]: spp_portscan:
PORTSCAN DETECTE
D from 206.251.0.173
Jun 7 13:32:59 www-cache.lshtm.ac.uk snort[632]: spp_portscan: portscan status
from 206.251.0.173: 1 connections across 1 hosts: TCP(1), UDP(0) STEALTH
Jun 7 13:33:06 www-cache.lshtm.ac.uk snort[632]: spp_portscan: End of portscan
from 206.251.0.173
using snort, obviously, and generated from
our machine that acts as our site 'web-cache/proxy'...
this was followed by about 3/4 other similar 'scans'
acknowledged by snort...
What interested me was the source of the addresses:
LucasArts Entertainment Company (LUCASARTS-DOM)
(NETBLK-LOCO-NET-LUCASARTS)
PO Box 10307
San Rafael, CA 94912
US
Netname: LOCO-NET-LUCASARTS
Netblock: 206.251.0.128 - 206.251.0.191
...
has anyone else seen this kind of activity,
and can the snort portscan detection be trusted?
Thanks....
--
---------------------------------------------------------------->
Peter Bates, Systems Support Officer, Network Support Team.
London School of Hygiene & Tropical Medicine.
Telephone:0207-927 2124 / Fax:0207-436 5389 / Pager: 07625 255362
Received on Jun 08 2000