Security Incidents mailing list archives
Re: Korea (again)
From: tmolina () HOME COM (Thomas Molina)
Date: Thu, 27 Jan 2000 17:41:51 -0600
On Thu, 27 Jan 2000, Kim Roland Rasmussen wrote:
Just out of curiosity, what Korea are y'all referring to? .kp or .kr ?All of the scannings we've had are from the .kr domain.
I've seen scans from .kr addresses which resolve (according to apnic) to korea telecom isp nodes. In addition, I've seen scans for port 1080 proxy servers from .korea.mil addresses. Makes me wonder if some army nodes have been compromised.
Current thread:
- Re: Strange DNS/TCP activity, (continued)
- Re: Strange DNS/TCP activity Asmodeus (Jan 27)
- Re: Strange DNS/TCP activity Roy Pait (Jan 27)
- port 768 Guido A.J. Stevens (Jan 27)
- Re: port 768 Robert Graham (Jan 27)
- Re: Strange DNS/TCP activity technot (Jan 27)
- Re: Strange DNS/TCP activity Richard Bejtlich (Jan 27)
- Connect thru PIX & ports 1727, 2209, 9200 CL: Nelson, Jeff (Jan 27)
- Re: Korea (again) Kim R. Rasmussen (Jan 26)
- Re: Korea (again) zeek (Jan 27)
- Re: Korea (again) Kim Roland Rasmussen (Jan 27)
- Re: Korea (again) Thomas Molina (Jan 27)
- Re: Korea (again) Rob Quinn (Jan 28)
- Re: Korea (again) Granquist, Lamont (Jan 27)
- Re: Korea (was RE: ?) horio shoichi (Jan 26)
- Re: Korea (was RE: ?) David Brumley (Jan 27)
- Re: Korea (was RE: ?) Patrick Oonk (Jan 28)
- Re: Korea (was RE: ?) Arrigo Triulzi (Jan 28)
- Re: Korea (was RE: ?) Dug Song (Jan 28)
- Re: Korea (was RE: ?) Patrick Oonk (Jan 28)
- DNS update queries: another sort of suspicious activity. Fyodor (Jan 28)
- Re: DNS update queries: another sort of suspicious activity. Patrick Oonk (Jan 28)