Port scanning

Rath

Active Member
Joined
Mar 14, 2004
Messages
49
Reaction score
0
Location
.
I've been getting hammered every few minutes by a port scanner, here are the results of the backtrace/whois on the source IP:

OrgName: InfoSat (Pty) Ltd
OrgID: IFST
Address: 160 Jan Smuts Avenue, Rosebank
Address: Johannesburg, Gauteng 2196
City:
StateProv:
PostalCode:
Country: ZA

Anyone else getting this?
I get attacked every 10 mins or so(blaster variant and sasser and lovesan so far).
 
Well, my firewall be beating them off with a big stick - it's being handled. I'm just suprised at how prevalent this is.

Never been connected 24/7 before - it's pretty hectic.
 
lol yeah, my firewall has logged about 50 ports scans since yesterday. Seems to be comming from certain My Wireless users, hoping its just a virus and not someone trying to break in and steal my Barry Manilow mp3 collection :)

<b>in chaos all things are harmonious</b>
<i>Tower 82 14% Signal 512k package </i>
 
Kaos, I think you're pretty safe there [:D]

It's quite prevalent, even on my ADSL connection. When Sasser came out I got about 6Megabytes of scans on my DSL connection, and just a bit less on the Sentech interface.

If there was ever a time to run a firewall, now would be it.

<center><h5><font color="red">Oo. MyWireless <s>Hacks</s> Tweaks & Tech Info.oO </font id="red"></h5><h6>Have you checked the fawking FAQ?</h6></center>
 
"whats wrong with Barry Manilow ??"

Oh, uh... nothing. He's just so... POPULAR! Yeah! So everyone has his stuff already!

Yeah... yeah, that's it... [8D]
 
for those who havent experienced the horror, disgust, revulsion and pain that comes from listening to Barry Manilow - download the torrent file, use a Bit Torrent client - and grab the 'greatest' hits of the aforesaid Barry. Personally I'd go for root canal as a more positive alternative, but hey, different strokes, different folks :P
http://66.90.75.92/suprnova//torrents/1721/Barry_Manilow-Utimate_Manilow+covers-rar(2).torrent
 
/hides behind a rock

you're going to upset Kaptian Khaos and he's going to open a can of wuparse on you! :)

actually...

/gets the popcorn and lazyboy...

<hr noshade size="1"><font size="1"><i><center><font color="red">i haven't lost my mind, it's backed up on disk somewhere...</font id="red">
tower82.ranburg.jhb|13% signal|256k package</center></i></font id="size1">
 
any1 got any idea who it could be??

and no Kaptain Khaos I dout it is Barry Manilow looking for those who copy his music!!! [:D]
 
Just checked my Snort logs - also being port scanned from the 66.18.85.x subnet.

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">Date: 05/11 15:16:04 Name: spp_portscan: portscan status from 66.18.85.117: 8 connections across 1 hosts: TCP(8), UDP(0)
Priority: n/a Type: n/a
IP info: n/a:n/a -&gt; n/a:n/a
References: none found<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

Harmless unless you've got no firewall [:)]
 
yeah getting nailed too, but firewall soaking it all up. can someone explain to me in layman terms what it means that these guys are scanning our ports?
 
It's basically infected windows machines scanning for a new host to infect.

For instance, the Sasser worm and variations scan random IP addresses looking for open ports.
 
Damn #@%!@$ port scans !


OrgName: InfoSat (Pty) Ltd
OrgID: IFST
Address: 160 Jan Smuts Avenue, Rosebank
Address: Johannesburg, Gauteng 2196
City:
StateProv:
PostalCode:
Country: ZA

ReferralServer: rwhois://rwhois.infosat.net:4321

NetRange: 66.18.64.0 - 66.18.95.255
CIDR: 66.18.64.0/19
NetName: INFOSAT12-ZA
NetHandle: NET-66-18-64-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.MAILGATE.NET
NameServer: NS2.MAILGATE.NET
Comment:
RegDate: 2002-11-22
Updated: 2004-01-15

TechHandle: AR756-ARIN
TechName: Roussos, Angelo
TechPhone: +27 11 721 3800
TechEmail: [email protected]

OrgTechHandle: AR756-ARIN
OrgTechName: Roussos, Angelo
OrgTechPhone: +27 11 721 3800
OrgTechEmail: [email protected]

# ARIN WHOIS database, last updated 2004-05-15 19:15
# Enter ? for additional hints on searching ARIN's WHOIS database.


MyDraadloos -Base 36 Bedfordview Signal=9%patch Freq=2518 Gain99db

Pass the Pringles please !
 
People ....

A few comments. From what I'm seeing on my firewall logs I'd have to say there isn't so much a stack of "port scanning" going on as there is a HUGE amount of "worm spreading" going on.

Most of you will notice that the "scans" are only hitting a few specfic ports - mainly those related to M$ Window$ vulnerabilities.

As to doing a whois/traceroute etc etc. Just remember that the IP's from the INFOSat network also happen to include your OWN ip address... so while it MAY be a pc inside the infosat network (unlikely) its FAR more likely to be another MyWireless user infected with a worm.

Dbnnet - to the best of my knowledge INFOSat are NOT doing such scans - and IF any of their staff are doing so it is strictly speaking in violation of the AUP [:D]

Just a thought ...





************************************************************
The views expressed on this site are my own and NOT those of my employer.
 
I also get a lot of scans. Should I publish the IP addresses ? Some of them are foreign.

Maybe they can configure the network to log all communication with the non-existent IP addresses is the range (I'm sure there are a few, because there is less than 8192 MyWireless users). And then all traffic to and from those addresses should be banned (dropped).

That way the infected people will learn !


<hr noshade size="1">
<center>http://rational.co.za/MyWireless/calculate.html</center>
 
Unrealistic and idilic ;-)

Remember that we ARE on dynamic IPs. While we tend to keep the same IP for a couple of days at a time it certainly DOES change due to the nature of the dynamic allocation of IPs.

How would you feel if your access is curtailed ? [xx(][:(]

While I'm certain this is LOW on Setechs priority list I'd suggest you send a mail to [email protected] with the IP,date and time. Also include the port scanning details...

R

************************************************************
The views expressed on this site are my own and NOT those of my employer.
 
What you also may want to consider is to take a look at http://www.mynetwatchman.com. Basically he takes the (firewall) reports, goes through it for patterns and then mails the target. Nice idea.
 
Top
Sign up to the MyBroadband newsletter
X