From owner-freebsd-security Thu May 31 5:15:23 2001 Delivered-To: freebsd-security@freebsd.org Received: from hotmail.com (f45.law3.hotmail.com [209.185.241.45]) by hub.freebsd.org (Postfix) with ESMTP id 40C3B37B43F for ; Thu, 31 May 2001 05:15:20 -0700 (PDT) (envelope-from secure21st@hotmail.com) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Thu, 31 May 2001 05:15:20 -0700 Received: from 32.103.39.196 by lw3fd.law3.hotmail.msn.com with HTTP; Thu, 31 May 2001 12:15:20 GMT X-Originating-IP: [32.103.39.196] From: "WebSec WebSec" To: security@FreeBSD.ORG Subject: Port 21 Date: Thu, 31 May 2001 12:15:20 -0000 Mime-Version: 1.0 Content-Type: text/html Message-ID: X-OriginalArrivalTime: 31 May 2001 12:15:20.0164 (UTC) FILETIME=[5C3F0240:01C0E9CB] Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org

This past weekend my IDS and  honey pot picked-up stealth scans on port 21 to port 21.

I used a number of tools to "trace" IPs of scanners and they all pointed towards an asian organization.  (Understanding limitations of TCP, I do not think anyone will state that this means anything :( )

One of the honeypots was on a DSL assigned sub-net. IT makes me think that whoever scanned me was after residential computers.  (this  is no different from others except for IDS installed :) )

In my case all scans were "stealth".

Also, in my opinion it may not be a good idea to provide real IPs (at least in this list) because you never know how you can tip someone.  Yes, this is "security" by obscurity, but....

Hope this helps.

 

 

---------------------------------------------------------------------------------------------------------------------------------------------

My opinion is that unknown scanner was hoping to meet one of those admins who still use remote port of TCP/UDP packet as filter in

their firewall rules (like this: "ipfw allow tcp from any 21").

NKritsky - SysAdmin InternetHelp.Ru

http://www.internethelp.ru

e-mail: nkritsky@internethelp.ru

 

 

-----Original Message-----

From: Lim Seng Chor <Lim.Seng.Chor@sit.edu.my>

To: freebsd-security@FreeBSD.ORG <freebsd-security@FreeBSD.ORG>

Date: 31 мая 2001 г. 13:01

Subject: port 21

 

my kernel message showing:

Connection attempt to TCP 202.184.64.29:21 from

213.137.2.195:21

anyone can explain why 213.137.2.195 can use port 21 to connect

to my ftp port but not random port above 1024?

To Unsubscribe: send mail to majordomo@FreeBSD.org

with "unsubscribe freebsd-security" in the body of the message

 

 

To Unsubscribe: send mail to majordomo@FreeBSD.org

with "unsubscribe freebsd-security" in the body of the message



Get your FREE download of MSN Explorer at http://explorer.msn.com

To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message