Security Incidents mailing list archives

SMB scans


From: Ian Eure <ieure () SICKFUCK ORG>
Date: Thu, 27 Jul 2000 10:42:01 -0700

this morning, looking at what logcheck mailed me overnight, i came across
a _ton_ of these messages:

-- snip --
Jul 26 22:25:38 spindle kernel: Packet log: ltraf REJECT eth0 PROTO=17
203.12.167.242:137 aa.bb.cc.dd:137 L=78 S=0x00 I=16902 F=0x0000 T=112
(#13)
Jul 26 22:25:38 spindle snort: SMB Name Wildcard: 203.12.167.242:137 ->
aa.bb.cc.dd:137
-- snip --
looks like this went on for about 20 minutes. it also looks like the
source of the scan/attack was from a dialup in australia
(cbr-56K-242.tpgi.com.au)

not too worried about this, since the machine in question does not run
samba or any other smb daemon. but it blocks all traffic to ports <1024,
unless specifically allowed.

anyone else see anything like this?

--
 ______________________________________________
| "the whole scale of cosmic dimensions are falling from my mouth
| in the description of a kiss of the interimlovers"
|   - einsturzende neubaten, "interim"


Current thread: