[plug] One off FTP and Telnet attempts ?

Peter F Bradshaw pfb at users.sourceforge.net
Thu Nov 30 14:33:55 WST 2000


On Tue, 28 Nov 2000, Christian wrote:

> Yes, this is very common.  In fact, you'd probably see plenty of DNS
> and IMAP probes too if you had some way of detecting them.  People are
> continually scanning blocks of IP's looking for open ports that might be
> the entry point to a system.

The one that I do not understand is port taps on port 27374. According to
/etc/services this port is the:
"asp             27374/tcp                       # Address Search Protocol"

whatever that is. I don't now which software listens on that port. However,
it is a very popular port to tap and has been for some time. It must be a 
script that gets a lot of success.

There are a number of taps on ports 137 and 139 which are used by the Windows
Netbios system. People who are running Samba should beware!

Cheers

--
Peter F Bradshaw          | http://members.dingoblue.net.au/~pfb
pfb at users.sourceforge.net | PGP public key at
http://www.pfb.tsx.org    | http://members.dingoblue.net.au/~pfb/public_key.html
ICQ 75431157 (exadios)    | "Needs more salt" - Archimedes





More information about the plug mailing list