[plug] portscans

Bill Kenworthy billk at iinet.net.au
Tue Sep 25 21:50:19 WST 2001


I noticed what seemed like connection attempts from certain irc servers
on windows trojan ports soon after #1 son logged into them.  On
checking, it seems they scan common trojan ports on connect to make sure
the new entrant isnt exposed before allowing them into the channels.  I
can imagine if some irc servers do it, other services may follow if you
use them.

BillK

On Wed, 2001-09-26 at 13:22, Trent Lloyd wrote:
> I'd say its *probably* nothing to worry about - youll get scans and pings 
> etc all over the place - its only usually a worry if u get 100's at a time 
> (packeting) or repeated attacks or attempts over a long time
> 
> I can get 50 things in an hour and i get get 2 things in 4 hours (usually 
> the DALnet proxy scanner checking on connect is about it if i get little)
> 
> Im not saying disregard it, but its *probably* nothing to worry about
> 
> >The firewall logs show nothing for today.. Guess that means that the 61
> >entries were all unsuccessful attempts? Hope so!
> 
> they probablyu werent even attempts for much but to see if theres a box on 
> that ip or your isp pinging you - portscans well often come if your on IRC, 
> ICQ, AIM, MSN or something of the likes since they publish your ip publicly.
> 
> 
> ----------
> Trent Lloyd
> 
> My projects and associations -
>    http://www.irc-desk.net/ - Your IRC Resource for mIRC, Eggdrop and more...
>    http://www.variantrealities.com/ - VrS2 the most advanced mIRC script 
> around (private beta)
>    http://www.plug.org.au/ - Perth Linux Users Group
> 
> 
> 
> 





More information about the plug mailing list