Re: last 24 hour port scan log

From: The Other Guy (nospam@this.addy)
Date: 01/26/03


From: The Other Guy <nospam@this.addy>
Date: Sun, 26 Jan 2003 16:00:44 GMT

On Sun, 26 Jan 2003 14:01:43 GMT, while waiting for Somebody Else to
show up and say something, The Other Guy responded to a post from
Leythos <void@nowhere.com> who wrote in alt.computer.security:

>In article <v37pqqd80ae4c7@corp.supernews.com>, neosadist@hotmail.com
>says...
>>
>> "Leythos" <void@nowhere.com> wrote in message
>> news:MPG.189d07a47fa663ed989967@news-server.columbus.rr.com...
>> > Here's what I've recorded from my (Inbound only) firewall logs for the
>> > last 24 hours on my home network.
>> >
>> > It would be nice if most ISP's blocked inbound 137 & 139, that would
>> > remove about 90% of the log :)
>>
>>
>> FOR NEWBIES:
>
>I should have thought of that - I could modify the stored proc to show
>the service type attached to the port. I may do that later today.
>[snip]
>
>By the way - 25 is inbound, so it's not used inbound by Outlook or other
>mail readers. It's used to send mail from one server into another - so
>people scanning 25 are looking for an open mail server, or are sending
>mail to the server on the inbound network.

It's interesting that 110 is never probed -- nobody wants to read your
(cold comfort, I know), but everybody wants to use your 'mail
carrier'.

Also of note, in a 48 hr period you have 30 times more hits for WIN
File sharing than for your web site (And I'm thinking the last few
hours the hits are more you doing 'real time' checks from elsewhere or
testing that feature). Are you running SSL or are the https hits
attempting exploits on that service (there was a rash of those when
the vuln. came out not too long ago).

Finally, how many just above 1024 are apps you are using that require
a connection to the outside.

-- 
./configure --prefix=~/zyterion
Not this guy or that guy, The Other Guy.
This spot may contain a satirical comment or comedic source,
and is meant to be funny. If you are easily offended, gullible
or don't have a sense of humour we suggest you read elsewhere.


Relevant Pages

  • Re: NFS client/buffer cache deadlock
    ... Mknod Fsstat Fsinfo PathConf Commit GLease Vacate Evict ... Attr Hits Misses Lkup Hits Misses BioR Hits Misses BioW Hits Misses ... Server Ret-Failed ...
    (freebsd-stable)
  • Re: Few question regarding SBS setup
    ... I am confused RE the setup...So you have 1 inbound box for the whole ... It sounds like you would need Outlook ... outbound SMTP server would be your ISP's mail server. ... the POP3 connector in Exchange. ...
    (microsoft.public.windows.server.sbs)
  • Re: not the crypt
    ... the number of hits on the robot parts of the server ... I routinely get more hits today than ever before. ... Not quite so with usenet. ... click on links as the read the posts - doesn't really mean they are ...
    (comp.robotics.misc)
  • Re: Your suggestions about this Dell configuration?
    ... Websites with 3-4 million hits per month with video ads. ... either Apache or MySQL stops responding. ... Server Configuration: ... from/to disk, then your disks could get a thrashing. ...
    (freebsd-questions)
  • Re: Possible worm...please help
    ... different ways to help secure your server:. ... I had started to notice that out bound emails ... The inbound SMTP queue currently exceeds 4000 items. ...
    (microsoft.public.exchange.admin)

Quantcast