Re: Port Scans and Prelude

From: Shawn Belcourt (shawn_belcourt@wssl.com)
Date: 02/25/03


From: "Shawn Belcourt" <shawn_belcourt@wssl.com>
Date: Tue, 25 Feb 2003 18:04:58 GMT

You are right about mentioning that.
"Wojtek Walczak" <gminick@hacker.pl> wrote in message
news:b3g09k$n5c$1@atlantis.news.tpi.pl...
> Dnia Tue, 25 Feb 2003 14:29:05 GMT, Shawn Belcourt napisał(a):
> > I recently installed the Linux MNF firewall.
> ...and you're crossposting to inform everybody.
>
> > logs is udp scan attacks from my own ISP.
> Scan is not an attack.
>
> > When I asked the ISP to explain. They stated it was thier dhcp server
> > trying to see if the server was still alive.
> Strange. I thought dhcp uses ports 67 and 68 (of course there's a
> possibility to change them).
>

> > I have never heard of DHCP using port scans to see if a server is alive
> > before.
> What's your definition of scanning ?
Enumerating ports 1112-111119

      Quick Description Scanning attack
      Date Tue Feb 25 08:10:55 2003
      Kind Should be ok
      Received 1 time
      Message Udp scanning attempt: 39 cnx from port 1112 to 11119 in 13
seconds

>
> --
> [ ] gminick (at) underground.org.pl http://gminick.linuxsecurity.pl/ [ ]
> [ "Po prostu lubie poranna samotnosc, bo wtedy kawa smakuje najlepiej." ]



Relevant Pages

  • Re: webserver in linux at home ?
    ... Your ISP probably *doesn't care* if you run a low-traffic ... IP addr, but as mentioned above, using dyndns and ddclient, ... was a power failure due to misapplication of my finger. ... Up until a few months ago, I got much traffic from attacks ...
    (comp.os.linux.misc)
  • Re: Telnet: route to host
    ... >out why we couldn't reach anything on the internet - pings failed ... Or switch to an ISP that knows and understands networking. ... I see regular attacks on my machine, ... As to adding IPs to your filters you may find that your filters get ...
    (comp.unix.sco.misc)
  • Re: isp Re: intrusion via ssh
    ... >dont forget to add the isp to the list to file against if they were ... worm or some variation on it, and the ddos attacks comeing from their ... One of our clueless sales types insisted she hadn't opened a message ... The ISP refused to disconnect a good customer, and the customer, when ...
    (Debian-User)
  • Re: What to do about attacks?
    ... Lloyd Andrew schrieb: ... >attacks a week. ... Now I am getting hit about every five minutes. ... >customers sharing my ISP, I reported the addresses to my ISP, but they ...
    (comp.security.firewalls)
  • RE: Denial of service question.
    ... I have been the target of DoS attacks in the past. ... If a particular IP address is being targetted, make your ISP drop all ... How possible is it for us to put a firewall BEFORE the T1 line to block all of this before it hits our poor little line, ...
    (Security-Basics)