Security Incidents mailing list archives
Re: port 119
From: vev () MICHVHF COM (Vince Vielhaber)
Date: Wed, 5 Jan 2000 12:43:51 -0500
On Tue, 4 Jan 2000, Thomas Molina wrote:
The interesting thing to me is the change in pattern I've seen. Port scans for port 1080 at my location are quite common. I've got logs back 90 days; Through the end of December I only see one scan for port 119. I've seen three separate incidents since the 1st of January.
I recently had a number of scans on port 119, it turned out to be a customer's newsreader being pointed at the wrong host (www. instead of news.). Not sure what newsreader he was using though - just that he was running NT at the time. Vince. -- ========================================================================== Vince Vielhaber -- KA8CSH email: vev () michvhf com http://www.pop4.net 128K ISDN: $24.95/mo or less - 56K Dialup: $17.95/mo or less at Pop4 Online Campground Directory http://www.camping-usa.com Online Giftshop Superstore http://www.cloudninegifts.com ==========================================================================
Current thread:
- Re: ICMP time exceed in-transit packets White, Tim (Dec 31)
- Re: ICMP time exceed in-transit packets Chris Brenton (Jan 01)
- Re: ICMP time exceed in-transit packets Alain Thivillon (Jan 01)
- Re: ICMP time exceed in-transit packets Christopher Wilson (Jan 02)
- port 119 Dariusz Zmokly (Jan 03)
- Re: port 119 Robert Graham (Jan 03)
- Re: port 119 Thomas Molina (Jan 04)
- Re: port 119 Vince Vielhaber (Jan 05)
- Re: ICMP time exceed in-transit packets Alain Thivillon (Jan 01)
- Ports 25092 / 20869 Vanja Hrustic (Jan 04)
- Re: Ports 25092 / 20869 Robert Graham (Jan 04)
- port 1150 and 4833 ? Kim R. Rasmussen (Jan 04)
- Re: port 1150 and 4833 ? Frameloss, Frameloss (Jan 10)
- Re: ICMP time exceed in-transit packets Chris Brenton (Jan 01)
- Re: port 119 R a v e N (Jan 05)
- Re: port 119 Scott Laws (Jan 04)
- Writeup: it. TLD going astray Arrigo Triulzi (Jan 03)
- Computer Forsenics System Administrator (Jan 03)
- Re: Computer Forsenics-> www.fish.com/forensics mike (Jan 03)
- traceroute ICMP packets Laszlo Fabian (Jan 04)