Constant Hacking Attemps - Pacific Bell DSL customer

From: Neko (Neko@nospam.com)
Date: 02/06/02


From: Neko <Neko@nospam.com>
Date: Wed, 06 Feb 2002 04:59:53 GMT

x-no-archive: yes

I have basic dsl service from Pacific Bell in California with a
dynamic IP address. I use ZoneAlarm Pro as a for Firewall and just
installed Zone Analyser to review my logs. I was recently reviewing
old ZoneAlarm logs with Zonelog as far back as 2000 (ok, I was bored
and I had new toy) and found I've been attacked at min.4 times a day
and up to 10 times daily.

The attacks are coming from China, Germany, France, Russian, Korea,
Taiwan + AOL, Pacbell and it's partners + other US sites (including
Petfood Direct!).

What can be expected from an ISP to keep hackers coming through their
Firewall? Can't they afford Checkpoint? <grin> I've been report these
attempts to the Network Admins of the offenders with good feedback and
several machines removed from networks (an .EDU in New Mexico).
Pacbell only sends an auto-reply to my report.

What is Zone Alarm NOT protecting? At one point I was running Black
Ice Defender + Zone Alarm.......Is Zone Alarm enough?

The firewall is stopping these hacking attempt::

Port: 1394 (GoFriller, Backdoor G-1
Porrt: 31337 (Back Orifice "elite")
Port: 28431 (Hack-a-tack)
Port: 137 (NetBIOS, name service, nbtstat)
Port: 139 (NetBIOS, File and Print Sharing)
Port 12345 (Netbus)
 Port: 20034 (Netbus2pro)
Port: 1035 (Multidropper)
 Port: 1807 (SpySender)
Port: 1097 (RAT)
Port:s 1080, 1082 (WinHole)
Port: 1966 (Fake FTP)
Port: 1969 (OpC BO)
Port: 21 (FTP)
Port: 53 (DNS)
Port: 1243 (Sub-7)
Port: 27374 (Sub-7

Scans:
Port: 111 (sunrpc, portmap, rpcbind)
Port: 23 (Telnet)
Port: 1049 (sbin/initd
Port: 5632 (pcAnywhere)
Port: 515 (Linux)



Relevant Pages

  • Re: Cant access site from internet
    ... I finally realized that it was a firewall issue after all :-and now I can access the web site perfectly from LAN and WAN. ... on which port do you try to access to your site from LAN? ... Internal URL: http://mycomputername:50000 ... Public URL for Zone: http://mydomain.dyndns.com:50000 ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Cant access site from internet
    ... on which port do you try to access to your site from LAN? ... I already checked the firewall. ... Internal URL: http://mycomputername:50000 ... Public URL for Zone: http://mydomain.dyndns.com:50000 ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: router port forwarding ssh to a zone
    ... linksys router, I forwarded port 9022 to the zone's IP. ... Port 22 is forwarded to my global zone. ...
    (comp.unix.solaris)
  • Re: Cant access site from internet
    ... on which port do you try to access to your site from LAN? ... > Zone: Internet ... > Internal URL: http://mycomputername:50000 ... I could install WSS on it, and set up a site properly, but can't manage to access it from the internet. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Routing, Bridging and VPN
    ... In shorewall you generaly define one ZONE for each interfacace like ... Port 5000 i use for incoming VPN conections. ... create interface tun0, that you use in shorewall configuration. ...
    (Debian-User)

Quantcast