Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: Full Plate of Crow

Re: Full Plate of Crow

From: Russell Fulton <r.fulton_at_auckland.ac.nz>
Date: Thu, 02 Aug 2001 07:09:58 +1200

On Wed, 01 Aug 2001 11:52:09 -0400 Chris Brenton <cbrenton_at_altenet.com>
wrote:

> Alfred Huger wrote:
> >
>
>
> > Alot of the people mailing me last night and this morning were sending
> > firewall logs, not IDS logs.

I'm one of them.

>
> Agreed again. No packet decode, no confirmed hit. Otherwise we'll be
> looking at greatly skewed numbers. Using that criteria I could claim
> 14K+ Code Red infected systems back in April (oh wait, Code Red was not
> even around yet... ;).
>
I aso agree the we can not be certain that these are CR probes without
IDS fingerprints. That said my data (from argus logs) measuring SYN
packets to non existant/firewalled machines shows and expoential
increase starting at midnight UTC and now I am seeing over 40,000
individual ips probing on port 80. Starting at ^:35 (utc + 1200) I am
also seeing hits on the snort .ida rules ( 70 in the last half hour).

All very odd!!

Russell Fulton, Computer and Network Security Officer
The University of Auckland, New Zealand

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Aug 01 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos