Re: Scans of port 2002 - globe service

From: Duncan Patton a Campbell is Dhu (campbell@neotext.ca)
Date: 08/19/02


From: "Duncan Patton a Campbell is Dhu" <campbell@neotext.ca>
To: searle@unt.edu, freebsd-security@FreeBSD.ORG
Date: Mon, 19 Aug 2002 13:40:13 -0600

At first glance this looks like a distributed denial of service
attack,
possibly kicked off by the apache worm. Affect any but the most
recent apache versions. Look for a .a or .uua files in /tmp to
see of you are provoking it.

Duncan Patton a Campbell is Duibh ;-)

---------- Original Message -----------
From: Curry Searle <searle@unt.edu>
To: freebsd-security@FreeBSD.ORG
Sent: Mon, 19 Aug 2002 12:41:10 -0500
Subject: Scans of port 2002 - globe service

> Starting this morning, I've noticed MANY failed
> attempts coming through for requests to UDP port 2002.
>
> Begin sample from logs:
>
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 212.154.26.10:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 210.188.196.40:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 202.158.39.190:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 63.217.26.26:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 63.217.26.32:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 203.187.15.21:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 194.193.195.70:2002
> Aug 19 12:34:04 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 212.204.227.201:2002
> Aug 19 12:34:05 davinci /kernel: Connection attempt to
> UDP *myipaddress*:2002 from 202.206.100.38:2002
>
> End sample from logs:
>
> From the time-stamps, it appears that ~100 hosts are
> making this request once every minute. Anyone else
> experiencing this behavior? I have noticed that all
> the hosts I checked using Netcraft were running some
> version of unix, mostly FreeBSD and all were running
> apache with PHP.
>
> --
> ____________________________________________________
> Curry Searle | Postmaster
> searle@unt.edu | Unix Hosts
> www.cas.unt.edu/~searle | Xiotech Support
> College of Arts & Sciences | Win32 Desktop & Server
> Computer Support Services | Network HW & Protocols
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the
> message
------- End of Original Message -------

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: ipfilter traffic blocking and tcpdump snort etc
    ... > Maybee an upgrade of apache would be a good start?. ... Gets me that something as simple as a flood of packets can just ... from the attacking hosts with snort during the packet attack only had the SYN ...
    (freebsd-questions)
  • Re: Setting up Apache
    ... > for my sending them an additional fee each month. ... > I presently have two web sites that are being hosted by two different web ... > My problem is that I have no working knowledge of Apache. ... Anyway, if you get that far, read the "virtual hosts" ...
    (freebsd-questions)
  • Re: apache virtual host on a private machine
    ... In that light I want to figure out how to do IP-based virtual hosts ... This is more of an IIS group question, as I mentioned in my original ... Yes, Apache is a very popular web server, but keep in mind where did you ...
    (microsoft.public.windows.server.dns)
  • Setting up Apache
    ... I presently have two web sites that are being hosted by two different web ... hosts. ... My problem is that I have no working knowledge of Apache. ... I am presently running FreeBSD 5.2.1 if that makes any difference. ...
    (freebsd-questions)
  • Re: Figuring out redhat-config-httpd
    ... Alexander Dalloz wrote: ... If you have 2 lines in hosts with the same IP address it often does not ... >>into the URL field in Mozilla it's not telling Apache the right thing? ... >might be to detect Apache working using telnet: ...
    (Fedora)