Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: big increase in ftp scanning

Re: big increase in ftp scanning

From: Russell Fulton <r.fulton_at_AUCKLAND.AC.NZ>
Date: Sun, 12 Nov 2000 13:19:51 +1300

On Thu, 9 Nov 2000 11:04:28 +0100 Jan Muenther <jan_at_RADIO.HUNDERT6.DE>
wrote:

> Hi,
>
> > <aol>Me too</aol>. I have seen repeated DNS over TCP, ftp and other
> > scans from dip.t-dialin.net addresses. Complaints to abuse_at_t-ipnet.de
> > get zero response. In the end I just blocked 212.185.223.0/24.
>
> You should try and send your complaints to abuse_at_t-online.de.
> These guys generally do a good job, if you provide accurate logs.
> Might be more "responsive" if you talk to them in German, which I
> am willing to do in case you want me to.

I have also seen a lot of activity from this block -- latest is a ftp
scan of our entire /16 yesterday. I have always had automated
response followed by personal followup to my complaints to
abuse_at_t-online.de. In my complaints I alway supply accurate times (GPS
sync'ed) and actual log records. I suspect many ISP simply black hole
any report that does not have both.

That said we do see a lot of activity from this block so I do wonder
how effective their enforcemnet is.

Russell.
Received on Nov 13 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos