Security Incidents mailing list archives

Re: A slap on the wrist...?


From: Steve Stearns <sterno () BIGBROTHER NET>
Date: Thu, 31 Aug 2000 14:19:12 -0500

I still maintain that if you see a scan with fairly obvious malicious
intent and you have the time (which probably most of us don't), report
it.  You may well be doing someone the favor of letting them know their
box has been compromised.  This isn't trigger-happy, this is seeing the
neighbor's kid trying to break into cars, however incompetently, and
giving the neighbor a friendly call knowing they probably don't want their
kid doing this.  Personally, I'd want to know.

Generally what I do when I get a port scan is try my best to track it down
to a source using ARING and nslookup.  More often than not the source is
some dynamically assigned adress on some huge network and is almost
impossible to trace to an individual.  Ocassionally though I have had some
incidents go rather well.

One time I saw somebody trying to connect to RPC on my box which is very
much firewalled.  This time the trace yielded a static IP address for
somebody's mail server.  They were running a very old linux kernel (2.1.X)
and apparently hadn't done much for security patches and of course they
had been owned by somebody. I let them know what happened and they were
very greatful to know what had happened and even asked me for advice on
how to prevent it.

So, if you have the time, it's nice to track even random skip kiddy
scans.  It probably doesn't matter to you but it might matter to the
person who owns the box on the other end of the scan.

---Steve


Current thread: