From owner-freebsd-isp Sun Jul 9 10:54: 0 2000 Delivered-To: freebsd-isp@freebsd.org Received: from durango.picus.com (durango.picus.com [209.100.20.19]) by hub.freebsd.org (Postfix) with ESMTP id AA96937B569 for ; Sun, 9 Jul 2000 10:53:54 -0700 (PDT) (envelope-from troy@picus.com) Received: from abyss [209.100.22.250] by durango.picus.com (SMTPD32-5.05) id AB851B2C0094; Sun, 09 Jul 2000 13:51:01 -0400 From: "Troy Settle" To: , Subject: RE: port 113(hack attack?) Date: Sun, 9 Jul 2000 13:53:16 -0400 Message-ID: MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0004_01BFE9AD.08280E00" X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0) X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700 Importance: Normal In-Reply-To: <200007081646540580.0158100A@web4.allunix.com> Sender: owner-freebsd-isp@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org This is a multi-part message in MIME format. ------=_NextPart_000_0004_01BFE9AD.08280E00 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Install identd. /usr/ports/security/pidentd It will make some things work a bit faster. IIRC, even sendmail and other MTAs will try an ident request these days. -- Troy Settle Network Analyst Picus Communications 540.633.6327 -----Original Message----- From: owner-freebsd-isp@FreeBSD.ORG [mailto:owner-freebsd-isp@FreeBSD.ORG]On Behalf Of David W. DeTinne Sent: Saturday, July 08, 2000 7:47 PM To: freebsd-isp@freebsd.org Subject: port 113(hack attack?) I have log_in_vain set in my rc.conf file. Ever since doing this I have witnessed all sorts of connection attempts to port 113, here are some examples; Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2132 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2133 Connection attempt to TCP 24.11.229.88:113 from 130.236.254.50:61744 Connection attempt to TCP 24.11.229.88:113 from 130.236.254.50:61746 Connection attempt to TCP 24.11.229.88:113 from 131.220.43.1:3056 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2211 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2228 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2229 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2234 Connection attempt to TCP 24.11.229.88:113 from 216.190.128.200:2250 Connection attempt to TCP 24.11.229.88:113 from 209.161.0.33:2966 Connection attempt to TCP 24.11.229.88:113 from 203.178.141.212:4723 The /etc/services file states that port 113 is used for a Authentication Service? My question is, what is happening here, is someone trying to access my system or is this normal? Thank You, David DeTinne ------=_NextPart_000_0004_01BFE9AD.08280E00 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable
 
Install = identd. =20 /usr/ports/security/pidentd
 
It will make some = things work a=20 bit faster.  IIRC, even sendmail and other MTAs will try an ident = request=20 these days.

--
  Troy Settle
  Network = Analyst
 =20 Picus Communications
  540.633.6327

-----Original Message-----
From:=20 owner-freebsd-isp@FreeBSD.ORG = [mailto:owner-freebsd-isp@FreeBSD.ORG]On=20 Behalf Of David W. DeTinne
Sent: Saturday, July 08, 2000 = 7:47=20 PM
To: freebsd-isp@freebsd.org
Subject: port = 113(hack=20 attack?)

I have log_in_vain set in my rc.conf file. Ever since doing this = I have=20 witnessed
all sorts of connection attempts to port 113, here are some=20 examples;

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2132

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2133

Connection attempt to TCP 24.11.229.88:113 from = 130.236.254.50:61744

Connection attempt to TCP 24.11.229.88:113 from = 130.236.254.50:61746

Connection attempt to TCP 24.11.229.88:113 from = 131.220.43.1:3056

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2211

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2228

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2229

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2234

Connection attempt to TCP 24.11.229.88:113 from = 216.190.128.200:2250

Connection attempt to TCP 24.11.229.88:113 from = 209.161.0.33:2966

Connection attempt to TCP 24.11.229.88:113 from = 203.178.141.212:4723

The /etc/services file states that port 113 is used for a = Authentication=20 Service?

My question is, what is happening here, is someone trying to access = my=20 system or is this normal?

Thank You,

David DeTinne

 

 

------=_NextPart_000_0004_01BFE9AD.08280E00-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-isp" in the body of the message