Martin byford wrote:
>
> Hi.. Group
>
> I had set up a alert feature in my firewall in such way if external hosts
> contact my firewall via telnet, ssh, ftp , http, https, smtp.  It will send
> alert to me and drop it. To my suprise that more than 80% alert are caused
> by http.  Do anyone know that why so many people contact us via http? Do you
> know any attack can be initialled by HTTP?  FYI, we didn't register our
> firewall IP in the internet domain and it is not a web server.
>
> Besides, I also found most of the traffic come from 61.X.X.X and our
> firewall IP is also in 61.X.X.X network. But we are in different country.
>
> Any idea?

It's not people scanning, it's worms. Do we forget so soon? Remember Code Red?
It's still out there. So are several other HTTP worms. Worms don't die, they
fade away... well, they really don't even do that. How many 1433 scans do we
still get from the MS SQL worms?

As for the pattern, most scans are "nearby" in IP space, that's how Code
Red's and several worms that "borrowed" much of its code and/or methods
work. The code for picking "random" random is weighted to scan hosts on
the same or close networks. It turns out to be a good strategy.

There are humans directing scans for HTTP too. They are probably looking
more for open proxies. I would guess they only account for a small fraction
of the HTTP scanning traffic.
--
Crist J. Clark                               [EMAIL PROTECTED]
Globalstar Communications                                (408) 933-4387

The information contained in this e-mail message is confidential,
intended only for the use of the individual or entity named above.
If the reader of this e-mail is not the intended recipient, or the
employee or agent responsible to deliver it to the intended recipient,
you are hereby notified that any review, dissemination, distribution or
copying of this communication is strictly prohibited.  If you have
received this e-mail in error, please contact [EMAIL PROTECTED]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to