RE: What's going on here?

From: Yonatan Bokovza (Yonatanat_private)
Date: Mon Aug 26 2002 - 08:54:06 PDT

  • Next message: wykkydat_private: "Re: What's going on here?"

    > -----Original Message-----
    > From: Jackie [mailto:JackieJat_private]
    > Sent: Saturday, August 24, 2002 02:57
    > To: incidentsat_private
    > Subject: What's going on here?
    > 
    > 
    > ZoneAlarm reported this burst, all from port 80 on a reserved IP
    > block. What the honk's going on?
    > 
    > 
    > FWIN,2002/08/23,18:47:42 -4:00 
    > GMT,10.60.1.102:80,xxx.xx.96.7:9176,TCP (flags:S)
    > FWIN,2002/08/23,18:47:42 -4:00 
    > GMT,10.10.2.105:80,xxx.xx.96.7:13682,TCP (flags:S)
    
    Someone is scanning a victim that's in reserved address-space,
    giving your address as decoy.
    
    see:
    http://www.rootshell.be/~helevius/nid_3pe_v101.pdf
    
    Regards,
    Yonatan.
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Aug 26 2002 - 11:11:12 PDT