Security Incidents mailing list archives

Re: hack attempts from korea and Sydney


From: root () DNS KIMMINAU ORG (Eric Kimminau)
Date: Thu, 10 Feb 2000 23:34:29 -0500


 Date:         Wed, 2 Feb 2000 20:29:34 -0500 (EST)
        ftp-hack_attempt-ftpd-210.178.9.125
 4  atm8-0-024.CR-1.uschcg.savvis.net (209.176.95.69)  38 ms  38 ms
41 ms
 5  atm8-0-021.CR-1.usnycm.savvis.net (209.83.222.45)  65 ms  65 ms
65 ms
 6  216.90.236.122 (216.90.236.122)  69 ms  67 ms  71 ms
 7  38.1.10.29 (38.1.10.29)  128 ms (ttl=244!)  127 ms (ttl=244!)  126
ms (ttl=244!)
 8  204.6.117.186 (204.6.117.186)  130 ms (ttl=243!)  129 ms
(ttl=243!)  128 ms (ttl=243!)
 9  krnic-gbs-h0-7.bb.nuri.net (203.235.119.102)  270 ms (ttl=243!)
290 ms (ttl=243!)  277 ms (ttl=243!)
10  inet-krnic-localT3.bb.nuri.net (203.231.80.134)  279 ms
(ttl=242!)  272 ms (ttl=242!)  275 ms (ttl=242!)
11  pubnet-oversea-fe1.kix.ne.kr (202.30.94.66)  276 ms (ttl=241!)
293 ms (ttl=241!)  271 ms (ttl=241!)
12  210.104.13.117 (210.104.13.117)  269 ms (ttl=240!)  292 ms
(ttl=240!) *
13  210.104.101.134 (210.104.101.134)  284 ms (ttl=239!)  291 ms
(ttl=239!)  295 ms (ttl=239!)
14  210.95.31.82 (210.95.31.82)  279 ms (ttl=238!)  294 ms (ttl=238!)
305 ms (ttl=238!)
15  210.178.9.125 (210.178.9.125)  430 ms (ttl=237!)  313 ms
(ttl=237!)  323 ms (ttl=237!)

 Date:        Wed, 2 Feb 2000 18:27:15 -0500 (EST)
        ftp-hack_attempt-ftpd-203.41.175.162

14  GigabitEthernet3-0.wel-core3.Perth.telstra.net (203.50.113.17)
329 ms  331 ms  330 ms
15  Pos1-0.ken-core1.Sydney.telstra.net (203.50.6.45)  379 ms  380 ms
377 ms
16  GigabitEthernet4-0.ken-core3.Sydney.telstra.net (203.50.13.10)
377 ms  378 ms  377 ms
17  GigabitEthernet0-0-0.pad-core2.Sydney.telstra.net (203.50.6.78)
312 ms (ttl=241!)  313 ms (ttl=241!)  312 ms (ttl=241!)
18  Fddi1-0.chw-core1.Sydney.telstra.net (139.130.249.6)  314 ms
(ttl=240!)  326 ms (ttl=240!)  315 ms (ttl=240!)
19  Fddi0-0-0.chw10.Sydney.telstra.net (139.130.36.231)  314 ms
(ttl=239!)  314 ms (ttl=239!)  313 ms (ttl=239!)
20  gatew2.onsite.telstra.net (139.130.39.98)  320 ms (ttl=238!)  319
ms (ttl=238!)  321 ms (ttl=238!)
21  203.41.175.162 (203.41.175.162)  322 ms (ttl=237!)  320 ms
(ttl=237!)  319 ms (ttl=237!)

 Date:         Wed, 2 Feb 2000 18:22:42 -0500 (EST)
        telnet-hack_attempt-telnetd-203.41.175.162

 4  atm8-0-024.CR-1.uschcg.savvis.net (209.176.95.69)  38 ms  39 ms
39 ms
 5  Serial4-1-0.GW1.CHI1.ALTER.NET (137.39.130.169)  38 ms  39 ms  38
ms
 6  105.ATM3-0.XR2.CHI4.ALTER.NET (146.188.208.150)  54 ms  40 ms  39
ms
 7  194.at-2-1-0.TR2.CHI2.ALTER.NET (152.63.65.78)  40 ms (ttl=248!)
41 ms (ttl=248!)  40 ms (ttl=248!)
 8  126.at-5-1-0.TR2.SAC1.ALTER.NET (152.63.1.194)  93 ms (ttl=247!)
93 ms (ttl=247!)  92 ms (ttl=247!)
 9  296.ATM6-0.XR2.SFO4.ALTER.NET (152.63.51.13)  96 ms  96 ms  97 ms
10  190.ATM8-0-0.GW5.SFO4.ALTER.NET (146.188.149.37)  96 ms  96 ms  98
ms
11  att-gcs-gw.customer.ALTER.NET (157.130.197.78)  100 ms  98 ms  96
ms
12  199.37.127.194 (199.37.127.194)  97 ms  96 ms  107 ms
13  205.174.75.70 (205.174.75.70)  332 ms  330 ms  330 ms
14  GigabitEthernet3-0.wel-core3.Perth.telstra.net (203.50.113.17)
331 ms  332 ms  331 ms
15  Pos1-0.ken-core1.Sydney.telstra.net (203.50.6.45)  376 ms  378 ms
378 ms
16  GigabitEthernet4-0.ken-core3.Sydney.telstra.net (203.50.13.10)
379 ms  378 ms  379 ms
17  GigabitEthernet0-0-0.pad-core2.Sydney.telstra.net (203.50.6.78)
309 ms (ttl=241!)  311 ms (ttl=241!)  311 ms (ttl=241!)
18  Fddi1-0.chw-core1.Sydney.telstra.net (139.130.249.6)  414 ms
(ttl=240!)  413 ms (ttl=240!)  347 ms (ttl=240!)
19  Fddi0-0-0.chw10.Sydney.telstra.net (139.130.36.231)  315 ms
(ttl=239!)  314 ms (ttl=239!)  313 ms (ttl=239!)
20  gatew2.onsite.telstra.net (139.130.39.98)  321 ms (ttl=238!)  319
ms (ttl=238!)  319 ms (ttl=238!)
21  203.41.175.162 (203.41.175.

--
========================================================================
Eric Kimminau   eric () kimminau org   "I speak my mind and no one
else's."



Current thread: