Martin byford wrote: > > Hi.. Group > > I had set up a alert feature in my firewall in such way if external hosts > contact my firewall via telnet, ssh, ftp , http, https, smtp. It will send > alert to me and drop it. To my suprise that more than 80% alert are caused > by http. Do anyone know that why so many people contact us via http? Do you > know any attack can be initialled by HTTP? FYI, we didn't register our > firewall IP in the internet domain and it is not a web server. > > Besides, I also found most of the traffic come from 61.X.X.X and our > firewall IP is also in 61.X.X.X network. But we are in different country. > > Any idea?
It's not people scanning, it's worms. Do we forget so soon? Remember Code Red? It's still out there. So are several other HTTP worms. Worms don't die, they fade away... well, they really don't even do that. How many 1433 scans do we still get from the MS SQL worms? As for the pattern, most scans are "nearby" in IP space, that's how Code Red's and several worms that "borrowed" much of its code and/or methods work. The code for picking "random" random is weighted to scan hosts on the same or close networks. It turns out to be a good strategy. There are humans directing scans for HTTP too. They are probably looking more for open proxies. I would guess they only account for a small fraction of the HTTP scanning traffic. -- Crist J. Clark [EMAIL PROTECTED] Globalstar Communications (408) 933-4387 The information contained in this e-mail message is confidential, intended only for the use of the individual or entity named above. If the reader of this e-mail is not the intended recipient, or the employee or agent responsible to deliver it to the intended recipient, you are hereby notified that any review, dissemination, distribution or copying of this communication is strictly prohibited. If you have received this e-mail in error, please contact [EMAIL PROTECTED] ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
