Security Incidents mailing list archives
Re: First china, now russia?
From: argathin () GMX NET (Thomas Ribbrock (Design/DEG))
Date: Tue, 1 Feb 2000 10:41:16 +0000
On Sun, Jan 30, 2000 at 03:13:32PM -0500, Joseph Geyer wrote:
I've been getting scanned quite frequently from china (I basically have the entire country blackholed now). Now they are coming from russia. The curious thing is, they are using very interesting destination ports. Here take a look:
[...]
problem there. But 118 and 224 still have me baffled.
I've seen port 224 being used (in fact my own machines use it...) for "Masqdialer", which is a daemon to control a PPP connection remotely: http://cpwright.villagenet.com/mserver/ HTH, Thomas -- "Look, Ma, no obsolete quotes and plain text only!" Thomas Ribbrock | http://www.bigfoot.com/~kaytan | ICQ#: 15839919 "You have to live on the edge of reality - to make your dreams come true!"
Current thread:
- Re: First china, now russia? Pavel Kankovsky (Jan 31)
- <Possible follow-ups>
- Re: First china, now russia? Chad Day (Jan 31)
- Re: First china, now russia? Dave Dittrich (Jan 31)
- Re: First china, now russia? Dmitry Alyabyev (Feb 01)
- Re: First china, now russia? Thomas Ribbrock (Design/DEG) (Feb 01)