wanadoo.fr's ip blocks

From: Aaron Wolfe (aaron@aaronwolfe.com)
Date: 12/18/01


From: "Aaron Wolfe" <aaron@aaronwolfe.com>
To: <incidents@securityfocus.com>
Date: Mon, 17 Dec 2001 20:10:20 -0500

Thanks to all who responded confirming that just about everyone in the world
is annoyed by FTP scans from wanadoo.fr.
I have received almost 100 emails already. Since many people have requested
any info I come across, I am posting this.
Playing with whois I have come up with the following list of networks that
seems to cover every host in my own logs and the logs that others have sent
me. My testing with random IPs in these nets shows reverse dns ->
*.wanadoo.fr. If anyone can improve or correct this list please let me know.
And if there is an easier way to get this info I'd sure like to know that
too.

*.wanadoo.fr:

80.8.0.0/14
80.12.0.0/15
164.138.0.0/16
193.248.0.0/14
193.252.0.0/15
194.51.238.0/24
212.234.25.128/27
217.128.0.0/16

-aaron

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Sendmail Hacked
    ... > connection which is weird because I didn't know I had ftp running. ... I checked the ftp logs and they've all been cleared. ... They trace the spam back to you by the ... need sendmail running, or FTP, or telnet. ...
    (comp.os.linux.security)
  • Re: How do I extract emails from log files
    ... Time and money suggest it's worth ... the technique involved is to force the replay of the logs you ... You really can't easily do this without taking the Exchange Server offline ... scale world....you write off the emails and move on. ...
    (microsoft.public.windows.server.sbs)
  • Re: Help -- Have I been rooted?
    ... I only allowed ssh, httpd, and ftp port forwarding to my ... machine for the past few days while I used a store bought router. ... I checked the router logs and was greeted by pages of stuff like this: ...
    (comp.os.linux.security)
  • Re: chat logs
    ... 1.Generally is good thing to enable the logs in your irc client. ... As for emails. ... >The Emergency Response Task Force assigned to our case asked parents to ...
    (Security-Basics)
  • Re: Question on Internet access of vsftp server
    ... > Pete Nesbitt wrote: ... >> you should check your logs, and also add a LOG entry to the firewall DENY ... >>Depending on your exact rules, add something like this, just blow your FTP ...
    (RedHat)