Re: Port 119 Scans

From: Gary Maltzen (maltzen@MM.COM)
Date: 07/31/01


Message-Id: <4.3.2.7.2.20010731073506.00b95ea0@pop.mm.com>
Date: Tue, 31 Jul 2001 07:43:28 -0500
To: incidents@securityfocus.com
From: Gary Maltzen <maltzen@MM.COM>
Subject: Re: Port 119 Scans

FWIW, I'm on @Home cable and about once every five hours I get probed to see if I'm running an NNTP server in violation of TOS.

Checking a multi-homed server I manage, I see lots of RPC, DNS, SQUID, TELNET, FTP and SMTP scans but *no* NNTP scans in the last three weeks.

-----Original Message-----
Hi,

I'm seeing a lot of port 199 scans lately (very many the last week) .. Is there some sort of news server exploit out? Or am I the only one seeing this?

I'm on ADSL with dynamic IP so I don't think they'd be targetting me personally.. I don't run a newsserver...

Thanks,
Tom

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Is it normal to have FWROUTE from port 119?
    ... > I installed a firewall for the first time, ZoneAlarm 2.6.261. ... > proceeded to do a little browsing on my dial-up connection. ... > reported a lot of connections from their NNTP server to a ...
    (comp.security.firewalls)
  • Re: OT but might be helpful
    ... instances of Gnus and I don't think it required SSL. ... Today, I had to switch to port 119, and not use SSL, ... this looking around for an NNTP server, so we can get access to ... using this I get abpmh again but no images. ...
    (rec.motorcycles.harley)
  • Re: How do I port forward through 2 remote hosts?
    ... You gave a port number. ... > the ssh command to connect to the second remote host B. ... I think means the NNTP server ... In the only place in this scenario where you type an ssh command: ...
    (comp.security.ssh)
  • Re: Flyscreens
    ... Champ wrote: ... It's not really a web proxy, they've just set their NNTP server to received and direct traffic over the one port that's unlikely to be blanket blocked by most organisations. ...
    (uk.rec.motorcycles)