Quick question re FTP activity

From: Timothy M. Lyons (lyonsat_private)
Date: Sun Nov 10 2002 - 02:20:53 PST

  • Next message: Christopher Wagner: "RE: 030 igetnet ignkeywords"

    I just brought this server online to lessen the stress on my web server,
    so I have to admit it's been a _long_ time since I ran FTP on anything.
    Can someone tell me what the user is trying to accomplish from the log
    excerpt below?
    
    --Tim
    
    ---
    "Leave the beaten path and dive into the woods.   
    You are certain to find something interesting."
    	-- Alexander Graham Bell (1847 - 1922)
    
    ---begin ftp log---
    Nov  9 08:53:15 envoy ftpd[2801]: USER anonymous
    Nov  9 08:53:16 envoy ftpd[2801]: PASS mat_private
    Nov  9 08:53:16 envoy ftpd[2801]: ANONYMOUS FTP LOGIN FROM p9.pub.ro
    [192.129.3.252], mat_private
    Nov  9 08:53:16 envoy ftpd[2801]: TYPE Image
    Nov  9 08:53:16 envoy ftpd[2801]: PORT
    Nov  9 08:53:16 envoy ftpd[2801]: refused PORT 10.0.0.248,1362 from
    p9.pub.ro [192.129.3.252]
    Nov  9 08:53:17 envoy ftpd[2801]: PASV
    Nov  9 08:53:17 envoy ftpd[2801]: SIZE
    /pub/mirrors/chkrootkit/chkrootkit-poster-a1.pdf
    Nov  9 08:53:17 envoy ftpd[2801]: REST 0
    Nov  9 08:53:17 envoy ftpd[2801]: REST 100
    Nov  9 08:53:17 envoy ftpd[2801]: RETR
    /pub/mirrors/chkrootkit/chkrootkit-poster-a1.pdf
    Nov  9 08:53:21 envoy ftpd[2801]: ABOR
    Nov  9 08:53:21 envoy ftpd[2801]: FTP session closed
    ---end log ---
    
    
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Nov 11 2002 - 18:30:42 PST