Re: Dlink.com.sg intrusion with worm??



On 10 Oct 2006, in the Usenet newsgroup comp.security.misc, in article
<eggpdo$npf$1@xxxxxxxxxxxxxxxxxxxxxx>, Unruh wrote:

What I cannot figure out is how an external IP can attack a 192.168.x.x
number.

Not familiar with attacks FROM port 21? The bad guys do it all the time.

] Intruder: www.dlink.com.sg(203.126.164.142)(21).

] Attacked IP: ACE(192.168.100.100).
] Attacked Port: 1149.

The latter is unroutable and there is no way it could get from any
external site to that computer. Ie, this attack MUST be internal.

No port forwarding?

Old guy
.



Relevant Pages

  • RE: autoblocking many ssh failed logins from the same IP....
    ... Defending Against Attacks ... ports can be bombarded with login attempts using common ID/PW ... To the firewall these all look like legitimate packets. ... The simplest defense is to change the port numbers these services ...
    (freebsd-questions)
  • Re: Blocking attacks from spoofed IP addresses
    ... cause a _Self_ Denial Of Service attack. ... Defeating Denial of Service Attacks ... of our DMZ servers, and had source IPs from our public DNS servers. ... Web services are on your port 80 and/or 443, ...
    (comp.os.linux.networking)
  • RE: Specification-based Anomaly Detection
    ... >Or highly polimorph attacks, yes. ... >defines a listening application, so we can profile ... What about apps that all tunnel over a single port? ... >actionable anomaly detection result. ...
    (Focus-IDS)
  • Re: Grafting a SSH auto-drop chain onto Arnos 1.8.3-RC1
    ... > hammering my machine with multiple attacks per second. ... to block those certain places from ever touching your ssh port (if you don't ... the patchomatic-ng and add alot of neat options to iptables. ... have not seen one single ssh attack since I moved my sshd off port 22. ...
    (comp.os.linux.security)
  • RE: Hacking to Xp box
    ... restricts most of the attacks that use anonymous connections. ... nessus found port 135 139 ... Audit your website security with Acunetix Web Vulnerability Scanner: ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
    (Pen-Test)