[plug] portscans
Bill Kenworthy
billk at iinet.net.au
Tue Sep 25 21:50:19 WST 2001
I noticed what seemed like connection attempts from certain irc servers
on windows trojan ports soon after #1 son logged into them. On
checking, it seems they scan common trojan ports on connect to make sure
the new entrant isnt exposed before allowing them into the channels. I
can imagine if some irc servers do it, other services may follow if you
use them.
BillK
On Wed, 2001-09-26 at 13:22, Trent Lloyd wrote:
> I'd say its *probably* nothing to worry about - youll get scans and pings
> etc all over the place - its only usually a worry if u get 100's at a time
> (packeting) or repeated attacks or attempts over a long time
>
> I can get 50 things in an hour and i get get 2 things in 4 hours (usually
> the DALnet proxy scanner checking on connect is about it if i get little)
>
> Im not saying disregard it, but its *probably* nothing to worry about
>
> >The firewall logs show nothing for today.. Guess that means that the 61
> >entries were all unsuccessful attempts? Hope so!
>
> they probablyu werent even attempts for much but to see if theres a box on
> that ip or your isp pinging you - portscans well often come if your on IRC,
> ICQ, AIM, MSN or something of the likes since they publish your ip publicly.
>
>
> ----------
> Trent Lloyd
>
> My projects and associations -
> http://www.irc-desk.net/ - Your IRC Resource for mIRC, Eggdrop and more...
> http://www.variantrealities.com/ - VrS2 the most advanced mIRC script
> around (private beta)
> http://www.plug.org.au/ - Perth Linux Users Group
>
>
>
>
More information about the plug
mailing list