Web Hosting Talk







View Full Version : Rackshack portscan - why I was contacted?


dabystru
05-02-2001, 02:35 PM
Hello,

I have a RaQ 4 with RackShack and got the e-mail below. I have 3 IP addresses on my RaQ but none of them is 216.40.212.18. I forwarded this to Rackshack (whom I believe this address belongs), but why was I contacted at all?

And what should I do about such activity if anything?

------------------------------ cut------------------------------
We recently monitored a scan of at least 26000 addresses in our domain.
The scan came from 216.40.212.18 and involved attempted connections to
multiple ports:
portmap (~26000 addresses scanned)
39168 (~10 addresses scanned)

The maximum scan rate was 1134 connections per second and I've included
a partial connection log below.

This activity is consistent with an attacker looking for known security
holes. This appears to be an *intentional abuse* of our systems. You're
listed as the contact(s) for the domain including 216.40.212.18. Please
investigate this activity and/or forward this message to the
appropriate people. I've also CCed CP-Abuse@LBL.GOV in case this is
part of a bigger picture.

> ---[times are Pacific Daylight Time (GMT-7)]---
> Apr 30 02:52:17 216.40.212.18 > 128.3.1.1/portmap
> Apr 30 02:52:17 216.40.212.18 > 128.3.1.6/portmap
> Apr 30 02:52:17 216.40.212.18 > 128.3.2.95/portmap
> Apr 30 02:52:17 216.40.212.18 > 128.3.1.3/portmap
> Apr 30 02:52:20 216.40.212.18 > 128.3.2.51/portmap
> Apr 30 02:52:20 216.40.212.18 > 128.3.2.94/portmap
> Apr 30 02:52:20 216.40.212.18 > 128.3.2.96/portmap
> Apr 30 02:52:20 216.40.212.18 > 128.3.2.97/portmap
> Apr 30 02:52:20 216.40.212.18 > 128.3.1.11/portmap
> Apr 30 02:52:17 216.40.212.18 > 128.3.1.226/portmap
> Apr 30 02:52:17 216.40.212.18 > 128.3.2.25/portmap
> ---- [connections deleted] ----
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.217/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.226/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.219/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.224/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.228/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.225/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.152/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.227/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.156/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.3.212/portmap
> Apr 30 02:52:26 216.40.212.18 > 128.3.5.138/portmap

Incident Response
Computer Protection Program
Lawrence Berkeley National Laboratory
------------------------------ cut------------------------------

IPC PRO
05-02-2001, 07:42 PM
It is possible someone was using you as a jump site. Have you checked to see if that IP has, indeed, been registered with your contact information???

innkeeper
05-03-2001, 12:01 PM
I experienced the same problem before too! Can anyone tell me (us) how can our servers be prevented from being used for port scanning, or other such stuffs that gets us into trouble?

steve93138
05-10-2001, 11:24 AM
Originally posted by innkeeper
I experienced the same problem before too! Can anyone tell me (us) how can our servers be prevented from being used for port scanning, or other such stuffs that gets us into trouble?

Yeah, I'd like to know more about this too.:eek:

IPC PRO
05-10-2001, 11:48 AM
This a great tool. You can block scans, see who sacnned you, block their IP from future scans, see who owns the address, get advICE, etc. There is a downloadable 30-day evaluation here at this link:

http://www.softwarelight.com/index.php?kategorija=Antivirus&sifra=BlackICE%20Defender

This program is great for home systems, too. They now have a dedicated server version. Check it out on their website.

Cheers!

- User interface support for Trusting IP address ranges
- New Attack signatures
- Advanced Firewall Settings in Tools (accept or reject IP/ports)
- New Detection tab (allows you to set trusted IP or ignore certain attacks)
- New VIEW menu function to "Freeze" or "Filter by attack severity" the display

FIXES/CHANGES

- Decoupled the TRUST function from the firewall function. Trusting an IP address now only means that BID will ignore attacks detected from that IP address. That IP address can still be blocked.
- Fixed issue related to trusted address entries disappearing from the trusted list.
- Fixed "Land Attack" false positives (false report of a land attack under certain scenarios).
- Corrected compatibility issues with Microsoft's RRAS.
- Fixed "filter failed" issue related to systems with the Microsoft C2 hot fix and Windows 2000 SP2.
- Resolved the occurence of erroneous dates on packet and evidence logs.
- Reduced false positives on DNS corrupt packets and ICMP echo with no request.

Visit the NetworkICE website at www.networkice.com to learn more about our full line of corporate and consumer security products.