Security Incidents mailing list archives
Re: Automated, Distributed Port Scan
From: epadin () WAGWEB COM (Ed Padin)
Date: Tue, 9 May 2000 14:16:22 -0400
When you get scanned by a bunch of hosts but only one seems to engage in two-way comm it's probably the nmap spoof/decoy option.
From nmap help screen:
"* -Ddecoy_host1,decoy2[,...] Hide scan using many decoys" It spoofs a bunch of addresses but only one is the real culprit. It's supposed to confuse the target admin by using all the addresses and making it hard to trace the real guy. In your case, it looks like you found the real address that was scanning you. I wouldn't worry about it too much tho. These types of scans happen all the time. There are thousands of script kiddies out there looking to exploit systems. You can go to www.samspade.org and find info on your culprit. I wouldn't complain to their ISP unless it keeps happening. It's probably not a bad idea to scan your network your self for known exploits.
-----Original Message----- From: E. Larry Lidz [mailto:ellidz () ERIDU UCHICAGO EDU] Sent: Monday, May 08, 2000 3:30 PM To: INCIDENTS () SECURITYFOCUS COM Subject: Automated, Distributed Port Scan We seem to have been the victims of what appears to be an automated distributed port scan. Over the weekend we were scanned for Netbus by 30 (or so) different machines. We have comfirmed that there was two-way tcp traffic to at least one host on our network, so we do not believe that the source was spoofed. Each scan scanned a different set of machines on our network. From a quick look, there appears to have been little to no overlap (that is, machinea was not scanned from any two different sources). Looking at the times and the source of the scans, most of the scans lasted almost exactly 20 minutes -- this makes me think that it is likely automated. Sometimes there were pauses between the scans, sometimes there wasn't. The scans came from a variety of sites, but generally standard targets -- ISPs, Brazil, Korea, Austria, etc. -Larry
Current thread:
- Odd scans of tcp port 12345, (continued)
- Odd scans of tcp port 12345 Russell Fulton (May 15)
- Re: Odd scans of tcp port 12345 Shadow Boxer (May 16)
- New or Variant Port 109 Scans Stephen P. Berry (May 15)
- Re: IP Black list? Patrick van Zweden (May 15)
- TCP low port scan Jose Nazario (May 15)
- Re: IP Black list? Joe McAlerney (May 15)
- Re: IP Black list? Omachonu Ogali (May 15)
- Re: IP Black list? Emre (May 15)
- Re: IP Black list? Ex Machina (May 15)
- Re: IP Black list? Keith Owens (May 16)