Port Snetry is great, It has really done the trick for a num,ber of
boxes I've had to work with.

1 drawback, it only kicks out after the person touches port 80, and
another one..not sure which, its late here....so if you can define in your
scanner (e.g. nmap) not to look at these 2 your fine to still scan.

 The
Gods Previously Read:

> I don't know why, but yes, safety in numbers maybe?
> 
> ----- Original Message -----
> From: Matt Allen <[EMAIL PROTECTED]>
> To: Stuart Hume <[EMAIL PROTECTED]>
> Cc: <[EMAIL PROTECTED]>
> Sent: Thursday, May 11, 2000 10:35 PM
> Subject: Re: [SLUG] Annoyed with port scanners...
> 
> 
> > Stuart,
> >
> > In my previous email i mentioned i have 2 colo's at Zip. They are being
> > portscanned by the same machines as yours are(tin.it). We are running
> > port Sentry (www.psionic.com). It drops the IPs from the route table and
> > adds in an IPCHAINS rule realtime and reports them to /var/log/messages.
> >
> > I'd assume whoever is doing it is doing LARGE subnets (ie 61.8.*.*)
> >
> > I dont know if that puts your mind to rest at all.
> >
> > Matt
> >
> > Stuart Hume wrote:
> > >
> > > Hello All,
> > >
> > > This is perhaps off topic, but during easter our network firewall was
> > > crashed by someone other than who it should have been.
> > > Having rebuilt it, and turned on *lots* of packet filtering and logging,
> > > have been amazed at the number of people who have been doing
> > > a) port scanning,
> > > b) attempting to telnet
> > > c) sending packets continuously to ports with known vulnerabilites (even
> > > though they are dropped), day after day.
> > >
> > > The following networks were the source, and someone has tried to either
> > > telnet to the firewall, or has been sending packets to ports with known
> > > vulnerabilities, time and time again.  I have notified the admins at
> each of
> > > the nets, but true to large corporate form (at least with the telcos)
> they
> > > couldnt be bothered even answering.
> > >
> > > attcanada.net
> > > dc.com.pl
> > > tin.it (telecom italia ?)
> > > topshell.net (shonky looking isp selling shell access)
> > > indosat.id
> > >
> > > I know that chances are these were just stepping stones for the
> malevolent
> > > person, but one thing that puzzles me:
> > > some ips have host names like "x5-Pad14-ecde.attcanada.net" or
> > > "ec-15ep.tin.it".
> > > Are these system generated host names, or assigned to dialin lines
> during
> > > connections, or ?
> > >
> > > Maybe this is all par for the course, give up trying to let anyone know,
> and
> > > I should just chalk it down to experience gathering? (this urks me as I
> know
> > > someone had root access on one of these networks, which I presume means
> they
> > > are compromised?)
> > >
> > > </rant>
> > >
> > > Top points for "progsoc.uts.edu.au", who read my vitriolic email, didnt
> > > ignore me, and despite it are off looking for clues, all less than 12
> hours
> > > after notifying them of being port scanned from there, and sending them
> log
> > > extracts.
> > >
> > > Stu
> > >
> > > --
> > > SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> > > To unsubscribe send email to [EMAIL PROTECTED] with
> > > unsubscribe in the text
> >
> > --
> > Matt Allen                                      Linux/PHP eCommerce
> > Solutions
> > Linux Worx                                      Linux Networking
> > www.linuxworx.com.au                            Consulting
> > [EMAIL PROTECTED]
> > 0413 777 771
> > --
> > SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> > To unsubscribe send email to [EMAIL PROTECTED] with
> > unsubscribe in the text
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 


--
Guy Taylor
Obsidian Systems
Cell: 083 357 3438
E-mail: [EMAIL PROTECTED]

Please terminate paranoia() at your favourite recursion level.

PGP PUBLIC KEY BLOCK:
Available at ftp://lava.obsidian.co.za/pub/keys/guyspubkey

                                                                  
                                                                       

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to