FTP scans from wanadoo.fr

From: Aaron Wolfe (aaron@aaronwolfe.com)
Date: 12/17/01


From: "Aaron Wolfe" <aaron@aaronwolfe.com>
To: <incidents@securityfocus.com>
Date: Mon, 17 Dec 2001 12:59:43 -0500


hello,

for some time (weeks if not months) several of our remote offices have been
logging connects attempts to port 21 from various ips that resolve to
(something).wanadoo.fr. since we have firewalls on many different networks
from several providers all logging these attempts, i'm fairly sure this is a
script randomly scanning ips. I even put up an FTP server on one box to see
what would happen if port 21 was open, it attempted to login as anonymous
but I didn't let it go any further.

I have made many attempts to contact Wanadoo regarding this. I have sent
them logs and friendly messages asking if there is anything I can do to help
or if they would like more information. Despite sending at least 5 messages
over the last several weeks, I have never received any response at all.

I have started gathering IPs and just blocking the networks as wanadoo seems
to be a french ISP with nothing of interest to any our our offices. but
obviously I'd like to be as specific as possible when passing out null
routes.

My questions, has anyone else noticed this? I am almost certain others
have. But more importantly, is there an easy way for me to find out all the
networks that belong to wanadoo so I can just block them all rather than
waiting for a connection from a host in each network? Sorry if that's a
dumb question, i am kind of new to this. (many thanks to this list! i have
learned alot!) Oh, and am I over reacting here? I know these probes happen
all the time, but when they happen at all 20+ of our sites coming from the
same network for several weeks... ?

-aaron

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: FTP scans from wanadoo.fr
    ... space and they have requested a list of source IPs involved in scanning ... with Wanadoo.fr management, and they need some data to go with it. ... >> I have started gathering IPs and just blocking the networks as wanadoo ... >> For more information on this free incident handling, ...
    (Incidents)
  • Re: FTP scans from wanadoo.fr
    ... now aware of the scope of the scanning activity from Wanadoo.fr network ... space and they have requested a list of source IPs involved in scanning ... with Wanadoo.fr management, and they need some data to go with it. ... >> I have started gathering IPs and just blocking the networks as wanadoo ...
    (Incidents)
  • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... Subject: RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! ... Seems to be the most common opinion of those who have no apparent experience with large networks. ... held no responsibility here, ...
    (Full-Disclosure)
  • Re: How to choose an IDS/FW MSS provider
    ... > have completely out of band management networks. ... >> With the obvious success of IPS technologies at the perimeter, ... > vendor market as a whole) get to learn from their mistakes and successes. ...
    (Focus-IDS)
  • RE: ICMP (Ping)
    ... Why do you assume that out of millions of Ips that respond, ... > almost) running a port scan those that reply. ... replies from a ping request. ... IP ranges with no target in mind, ...
    (Security-Basics)