Security Incidents mailing list archives
RE: annoying ftp probes
From: "NESTING, DAVID M (SBCSI)" <dn3723 () sbc com>
Date: Mon, 20 Aug 2001 14:50:57 -0500
I get a ton of these pretty regularly, and it doesn't appear targeted at "me" specifically. I have a number of systems logging to a central syslog daemon, and I will see FTP connection attempts on all of my systems virtually simultaneously. This tells me they're scanning netblocks for open FTP servers (likely parallelized, but still reasonably sequential). A decently configured IDS could detect this and block the offender from further accesses. I do occasionally have clients on IRC when this happens, but I am never able to correlate any scan with any user that's been on IRC at any time in the previous month. They're probably just plugging in huge netblocks and letting it run overnight. Classic script kiddie tool. David -----Original Message----- From: Mike Eheler [mailto:meheler () searchbc com] Sent: Monday, August 20, 2001 7:22 To: Jason Spence Cc: incidents () securityfocus com Subject: Re: annoying ftp probes It wouldn't be tough to create something like that, anyways. I bet it's just part of some "war" IRC script, or something. ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- annoying ftp probes Emil Popov (Aug 20)
- smtp probes Eduardo Cruz (Aug 20)
- Re: smtp probes Hugo van der Kooij (Aug 20)
- Re: smtp probes Wichert Akkerman (Aug 20)
- Re: smtp probes Hugo van der Kooij (Aug 20)
- Re: annoying ftp probes Jason Spence (Aug 20)
- Re: annoying ftp probes Mike Eheler (Aug 20)
- Re: annoying ftp probes Joris De Donder (Aug 20)
- <Possible follow-ups>
- RE: annoying ftp probes Mark Villanova (Aug 20)
- RE: annoying ftp probes Gregory McCann (Aug 20)
- RE: annoying ftp probes Skeeve Stevens (Aug 27)
- RE: annoying ftp probes Gregory McCann (Aug 20)
- RE: annoying ftp probes NESTING, DAVID M (SBCSI) (Aug 20)
- Re: annoying ftp probes Emil Popov (Aug 27)
- smtp probes Eduardo Cruz (Aug 20)
