Security Incidents mailing list archives
SMB scans
From: Ian Eure <ieure () SICKFUCK ORG>
Date: Thu, 27 Jul 2000 10:42:01 -0700
this morning, looking at what logcheck mailed me overnight, i came across a _ton_ of these messages: -- snip -- Jul 26 22:25:38 spindle kernel: Packet log: ltraf REJECT eth0 PROTO=17 203.12.167.242:137 aa.bb.cc.dd:137 L=78 S=0x00 I=16902 F=0x0000 T=112 (#13) Jul 26 22:25:38 spindle snort: SMB Name Wildcard: 203.12.167.242:137 -> aa.bb.cc.dd:137 -- snip -- looks like this went on for about 20 minutes. it also looks like the source of the scan/attack was from a dialup in australia (cbr-56K-242.tpgi.com.au) not too worried about this, since the machine in question does not run samba or any other smb daemon. but it blocks all traffic to ports <1024, unless specifically allowed. anyone else see anything like this? -- ______________________________________________ | "the whole scale of cosmic dimensions are falling from my mouth | in the description of a kiss of the interimlovers" | - einsturzende neubaten, "interim"
Current thread:
- SMB scans Ian Eure (Jul 27)
- <Possible follow-ups>
- Re: SMB scans Jonathan Stade (Jul 28)
