Re: Network abuse report

From: Diego Kellner (dkepler_at_gmail.com)
Date: 05/27/05

  • Next message: Kevin Snively: "aretzj.exe -- reappearing unknown system file"
    Date: Fri, 27 May 2005 13:25:49 -0300
    To: security-basics@securityfocus.com
    
    

    Definitely, port scanning as such is not a crime. Now, why would any
    valid user of my systems need to run a port scanning on my servers?

    Besides, my firewall rules are configured so that only the services I
    need are made public, so my concern is not that of someone finding an
    open port to a dangerous thing. I rely on my Internet connection for
    more than just web surfing, so the traffic these IPs add to my
    firewall has a negative impact on my WAN (availability).

    I might just block them in my routers and pretend they don't exist.
    However, there might be other people having the same problem because
    of these IPs (including the one doing the scans, that might be a
    zombie computer in a legitimate business company). If I can add my 2
    cents to "Internet traffic" by trying to stop this, I don't see why I
    shouldn't.

    On 5/27/05, Emmanuel Goldstein <goldstein101@gmail.com> wrote:
    > Oh Come on!, they're just port scans. You cannot avoid people scanning
    > your network, that's why you should try to improve your security every
    > single day. And don't think they are specificly scanning your network
    > 'cause many people scan millions of hosts everyday, eg: security audit
    > companies or people doing network security masters...
    >
    > Whether you like it or not, port scanning is not ilegal. Don't go
    > around reporting those really dangerous "Network abuses" ;-P
    >
    > On 5/26/05, Diego Kellner <dkepler@gmail.com> wrote:
    > > Hi, I am now encharged of analyzing firewall logs in my company, and
    > > I'm beggining frequent port scanning from certain IPs (most of them in
    > > Asia). I know it might not change a thing, but I'd like to report this
    > > IPs to their respective ISPs. Anyone has (or knows of a web site
    > > that's got) Network Abuse Mail Templates I could use?
    > > Regards,
    > > Diego
    > >
    >


  • Next message: Kevin Snively: "aretzj.exe -- reappearing unknown system file"

    Relevant Pages

    • Re: Difficulties in Network Mapping & port scanning
      ... Chapter 11 (Firewalls) of Hacking Exposed Network Security Secrets and Solutions is also worth a read as it touches on enumeration through a Firewall. ... Also a very interesting few paragraphs on using non-echo ICMP messages for host enumeration. ... Subject: Difficulties in Network Mapping & port scanning Date: Tue, ...
      (Pen-Test)
    • Re: Difficulties in Network Mapping & port scanning
      ... You can make certain conclusions as to what the operating system is, what firewall it is, and so on by probing ... Many publications detail nmap port scanning techniques but make many assumptions. ... Same applies to ICMP network mapping. ...
      (Pen-Test)
    • Re: [Full-disclosure] scanning
      ... One of the most common questions I get from crackers, hackers, network security specialists and law enforcement agents is whether port scanning is illegal. ... In Moulton v. VC3, Scott Moulton, a network security consultant, was arrested and charged with violating the Computer Fraud and Abuse Act after he port scanned a network where he had a service contract to perform computer-related work for the a county 911 center. ...
      (Full-Disclosure)
    • Re: Network Security Tool
      ... > I remember being at a friend's house and saw him using some win32 ... > application that combined a number of network security and diagnostic ... port scanning and a couple of others) on a Windows device. ... abilities like ping scanning a network, ...
      (comp.security.misc)
    • Re: Network Security Tool
      ... > I remember being at a friend's house and saw him using some win32 ... > application that combined a number of network security and diagnostic ... port scanning and a couple of others) on a Windows device. ... abilities like ping scanning a network, ...
      (comp.security.firewalls)