Security Incidents mailing list archives

Re: update on scans of tcp 12345 AUSCERT#36349


From: rune () TRANS4MEDIA COM (Rune Kristian Viken)
Date: Thu, 8 Jun 2000 12:28:52 +0200


On Mon, 05 Jun 2000, you wrote:
        I have now seen over 180 of these scans! 60 in the last 24
hours. One thing I have established since my last post is that these do
seem to be targetted at us.  I have not had anyone else contact me to
say that they have seen these and I contacted the network admin of one
of the neighbouring class Bs (another NZ university -- we got our
addresses at the same time) and they have not seen any of these scans.
Whether the targeting is deliberate of not is anyones guess.

There may be a simple explanation.  The port "12345" is the 'netbus-server'
standard-port.  A lot of IRC-"warscripts" scan for these.  If your users are a
lot on IRC, and they join large channels, especially efnet, undernet, dalnet
and ircnet - then they may be automatically scanned for it.

--
"Rune Kristian Viken" <rune () trans4media com> <http://arcade.kvinesdal.com>
System, Network & Security Administrator.  Phone: (+47) 92 85 34 38



Current thread: