Security Incidents mailing list archives

Re: Simultaneous Attacks


From: epadin () WAGWEB COM (Ed Padin)
Date: Fri, 7 Jul 2000 18:05:11 -0400


You should not post your IP address to this list as it will invite a whole
bunch more knuckleheads to bang on your door. The Netdoor probes are nothing
to worry about if you're running black ice. You can try complaining to the
ISP but it usually dddoesn't result in any action. They are too busy getting
complaints. If they keep hitting you over and over then maybe you have a
case but if it's a single scan they can easily claim it was an innocent
mistake. For example:
If I click start->run and type "telnet  24.161.11.47 12345"

it will trip the same message on your machine.

I usually tell black ice to ignore the IP address for a month but be careful
with this because it can also be a spoofed address. Let's say they spoof it
to come from www.yahoo.com, you won't be able to reach yahoo.

-----Original Message-----
From: Harlan S. Barney, Jr. [mailto:hsbarney () NYCAP RR COM]
Sent: Friday, July 07, 2000 12:27 AM
To: INCIDENTS () SECURITYFOCUS COM
Subject: Simultaneous Attacks


Today I have detected three simultaneous intrusions into my computer.
I report ALL intrusions and expect maximum penalties.

I am using the BlackICE program.

Record(s) from Attack-list.csv follow, date and time are GMT:
59, 2000-07-06 23:59:50, 2003103, NetBus port probe, 64.232.4.242, ,
24.161.11.47, , port=12345&name=NetBus, 6, A
59, 2000-07-06 23:59:50, 2003103, NetBus port probe, 23.23.23.23, ,
24.161.11.47, , port=12345&name=NetBus, 6, A
59, 2000-07-06 23:59:50, 2003103, NetBus port probe, 24.24.24.24,
tmp1-3218.twcny.rr.com, 24.161.11.47, , port=12345&name=NetBus, 6, A


It looks like an attempt to gain access by crashing my
computer.  The IP
23.23.23.23 is apparently unassigned in the European area.  It would be
interesting to know how widespread this attack was and who was really
behind it.

Harlan S. Barney, Jr.



Current thread: