Security Incidents mailing list archives
linuxconf scans from KR
From: infrastructure () NARELLAN NET (Infrastructure Dept.)
Date: Thu, 1 Jun 2000 10:08:03 -0400
Over the last few days I've seen several linuxconf scans from 210.112.192.74 which does not resolve. When I do a trace these are the last few lines before are 8 sl-concentric-1-0-T3.sprintlink.net (144.228.111.14) 113.237 ms 134.415 ms 126.932 ms 9 dacom-bora.cust.concentric.net (207.88.240.58) 124.633 ms 123.838 ms 116.644 ms 10 p4.bora.net (203.255.234.44) 138.781 ms 122.951 ms 130.380 ms 11 203.255.234.193 (203.255.234.193) 233.228 ms 256.677 ms 281.795 ms 12 selansp.rt.bora.net (210.120.192.137) 290.584 ms selansp-ge8-0-0.rt.bora.net (210.120.192.7) 269.681 ms selansp.rt.bora.net (210.120.192.137) 240.073 ms 13 selansp-h2-0-0-c.rt.bora.net (203.233.35.30) 232.020 ms 210.392 ms 227.212 ms 14 210.112.220.149 (210.112.220.149) 217.525 ms 240.881 ms 232.507 ms 15 210.112.220.68 (210.112.220.68) 280.919 ms 293.587 ms 281.271 ms 16 210.112.220.182 (210.112.220.182) 287.864 ms 280.791 ms 250.874 m sbora.net belongs to Dacom Corp in Seoul KR. I am using Black Ice on NT to see these scans. Funny thing is that scanlogd on the Linux box isn't reporting anything at all. I have however blocked all packets from this host at the router. <Stuff I pulled from BI log files> #Severity timestamp (GMT) issueId issueName intruderIp 39 2000-05-31 14:49:54 2003021 Linuxconf port probe 210.112.192.74 victimIp victimName parameters count x.x.x.x my.host port=98 3 EX::Tue, 30 May 2000 23:29:25: BI_DnsResolver: Host not found 210.112.192.74 err 11004 age ~BT2_Record(210.112.192.74) 620 seconds old EX::Wed, 31 May 2000 10:50:00: BI_DnsResolver: Host not found 210.112.192.74 err 11004 age ~BT2_Record(210.112.192.74) 347 seconds old
Current thread:
- POP3 (110) Port Scans, New Exploit? Crist J. Clark (May 29)
- linuxconf scans from KR Infrastructure Dept. (Jun 01)
- Re: POP3 (110) Port Scans, New Exploit? Chip Mefford (Jun 01)