Security Incidents mailing list archives

linuxconf scans from KR


From: infrastructure () NARELLAN NET (Infrastructure Dept.)
Date: Thu, 1 Jun 2000 10:08:03 -0400


Over the last few days I've seen several linuxconf scans from 210.112.192.74
which does not resolve. When I do a trace these are the last few lines
before are

8  sl-concentric-1-0-T3.sprintlink.net (144.228.111.14)  113.237 ms  134.415
ms  126.932 ms
 9  dacom-bora.cust.concentric.net (207.88.240.58)  124.633 ms  123.838 ms
116.644 ms
10  p4.bora.net (203.255.234.44)  138.781 ms  122.951 ms  130.380 ms
11  203.255.234.193 (203.255.234.193)  233.228 ms  256.677 ms  281.795 ms
12  selansp.rt.bora.net (210.120.192.137)  290.584 ms
selansp-ge8-0-0.rt.bora.net (210.120.192.7)  269.681 ms selansp.rt.bora.net
(210.120.192.137)  240.073 ms
13  selansp-h2-0-0-c.rt.bora.net (203.233.35.30)  232.020 ms  210.392 ms
227.212 ms
14  210.112.220.149 (210.112.220.149)  217.525 ms  240.881 ms  232.507 ms
15  210.112.220.68 (210.112.220.68)  280.919 ms  293.587 ms  281.271 ms
16  210.112.220.182 (210.112.220.182)  287.864 ms  280.791 ms  250.874 m

sbora.net belongs to Dacom Corp in Seoul KR. I am using Black Ice on NT to
see these scans. Funny thing is that scanlogd on the Linux box isn't
reporting anything at all. I have however blocked all packets from this host
at the router.

<Stuff I pulled from BI log files>

#Severity        timestamp (GMT)                issueId  issueName                       intruderIp
39              2000-05-31 14:49:54     2003021  Linuxconf port probe    210.112.192.74

victimIp         victimName      parameters     count
x.x.x.x my.host          port=98         3

EX::Tue, 30 May 2000 23:29:25: BI_DnsResolver: Host not found 210.112.192.74
err 11004
age ~BT2_Record(210.112.192.74) 620 seconds old
EX::Wed, 31 May 2000 10:50:00: BI_DnsResolver: Host not found 210.112.192.74
err 11004
age ~BT2_Record(210.112.192.74) 347 seconds old


Current thread: