Security Incidents mailing list archives

Re: First china, now russia?


From: argathin () GMX NET (Thomas Ribbrock (Design/DEG))
Date: Tue, 1 Feb 2000 10:41:16 +0000


On Sun, Jan 30, 2000 at 03:13:32PM -0500, Joseph Geyer wrote:
I've been getting scanned quite frequently from china (I basically
have the entire country blackholed now).  Now they are coming from
russia.  The curious thing is, they are using very interesting
destination ports.  Here take a look:
[...]

problem there.  But 118 and 224 still have me baffled.

I've seen port 224 being used (in fact my own machines use it...) for
"Masqdialer", which is a daemon to control a PPP connection remotely:
http://cpwright.villagenet.com/mserver/

HTH,

Thomas

--
             "Look, Ma, no obsolete quotes and plain text only!"

     Thomas Ribbrock | http://www.bigfoot.com/~kaytan | ICQ#: 15839919
   "You have to live on the edge of reality - to make your dreams come true!"



Current thread: