Security Incidents mailing list archives

Undernet/telnet attempts?


From: sec () FRENZY ORG (SecOrg)
Date: Fri, 18 Feb 2000 16:51:02 -0800


I have gotten a number of telnet attempts/scans on my server from undernet
IRC hosts. A couple of the hosts were
dallas-r.tx.us.undernet.org
ProxyScan.MD.US.Undernet.Org

As the name implies, I am guessing they are scanning wingates/proxies,
etc for security/eggdrop reasons. Does anyone know if they scan all
incoming connections for telnet(wingate) ports?  And if so, why they would
try to connect to it afterwards? Maybe some kind of fingerprinting
technique that would find out if it is a open wingate?
Thank you,

Randy McClelland-Bane
@Harborside Technical Support
1-800-680-8855


Current thread: