Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 3 Dec 1999 03:32:23 -0600
From:      BobF <FBob@wt.net>
To:        freebsd-questions@FreeBSD.ORG
Subject:   Portsentry-Attacks?
Message-ID:  <9912030336420S.00269@FBob.wt.net>

next in thread | raw e-mail | index | archive | help
If this query is posted to the wrong list, please advise.

Being a bit paranoid in this day and age I installed Portsentry to see
what/who  was trying to connect to my box. The results were a bit of a
shock and I am wondering if the reported attacks are in fact real. Here
is a sample of the blocked file generated by Portsentry:

944019385 - 11/30/99 21:36:25 Host: 98A903CE.ipt.aol.com/152.169.3.206 Port: 80 Blocked
944019618 - 11/30/99 21:40:18 Host: p3E9EDDA4.dip.t-dialin.net/62.158.221.164 Port: 80 Blocked
944020530 - 11/30/99 21:55:30 Host: dial56050.mtu-net.ru/195.34.56.50 Port: 80 Blocked
944020905 - 11/30/99 22:01:45 Host: a1as01-p41.stg.tli.de/195.252.185.41 Port: 80 Blocked
944021365 - 11/30/99 22:09:25 Host: cx32700-b.elcjn1.sdca.home.com/24.9.242.10 Port: 80 Blocked
944021729 - 11/30/99 22:15:29 Host: p3E9EDC1A.dip.t-dialin.net/62.158.220.26 Port: 80 Blocked
944021823 - 11/30/99 22:17:03 Host: 195.34.27.6/195.34.27.6 Port: 80 Blocked
944022705 - 11/30/99 22:31:45 Host: dyn-96-59.dialup.NevaLink.RU/195.190.96.59 Port: 80 Blocked
944022736 - 11/30/99 22:32:16 Host: cr664938-a.ym1.on.wave.home.com/24.114.114.117 Port: 80 Blocked
944022893 - 11/30/99 22:34:53 Host: p151.n77.dip.aha.ru/195.2.77.151 Port: 80 Blocked
944025201 - 11/30/99 23:13:21 Host: 195.128.152.151/195.128.152.151 Port: 80 Blocked
944025220 - 11/30/99 23:13:40 Host: 206-p1.Ascend02.STT.VIaccess.Net/63.64.76.206 Port: 80 Blocked
944025386 - 11/30/99 23:16:26 Host: p3E9EDC1E.dip.t-dialin.net/62.158.220.30 Port: 80 Blocked
944025774 - 11/30/99 23:22:54 Host: dp-4-113.TM.Odessa.UA/195.66.216.113 Port: 80 Blocked
944025810 - 11/30/99 23:23:30 Host: kletka2.sifibr.irk.ru/62.76.16.24 Port: 80 Blocked
944026385 - 11/30/99 23:33:05 Host: 195.239.92.101/195.239.92.101 Port: 80 Blocked
944026449 - 11/30/99 23:34:09 Host: 10.MD-6.dialup.orc.ru/212.48.131.202 Port: 80 Blocked
944026479 - 11/30/99 23:34:39 Host: p3E9EDC22.dip.t-dialin.net/62.158.220.34 Port: 80 Blocked
944026814 - 11/30/99 23:40:14 Host: dyn-97.cris.net/212.110.129.97 Port: 80 Blocked
944027595 - 11/30/99 23:53:15 Host: p3E9EDC1C.dip.t-dialin.net/62.158.220.28 Port: 80 Blocked
944207252 - 12/03/99 01:47:32 Host: 193.232.250.230/193.232.250.230 Port: 80 Blocked
944207949 - 12/03/99 01:59:09 Host: dyn-82.cris.net/212.110.129.82 Port: 80 Blocked
944208873 - 12/03/99 02:14:33 Host: 212.248.81.60/212.248.81.60 Port: 80 Blocked
944210354 - 12/03/99 02:39:14 Host: 195.7.187.246/195.7.187.246 Port: 80 Blocked
944211721 - 12/03/99 03:02:01 Host: p14.n88.dip.aha.ru/195.2.88.14 Port: 80 Blocked
944212021 - 12/03/99 03:07:01 Host: 213.24.5.168/213.24.5.168 Port: 80 Blocked
944212136 - 12/03/99 03:08:56 Host: 195.239.120.99/195.239.120.99 Port: 80 Blocked

Anyone have any input as to the authenticity of the alleged
"attacks" ? 


BobF

Email: FBob@WT.NET


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?9912030336420S.00269>