Security Incidents mailing list archives
Re: update on scans of tcp 12345 AUSCERT#36349
From: rune () TRANS4MEDIA COM (Rune Kristian Viken)
Date: Thu, 8 Jun 2000 12:28:52 +0200
On Mon, 05 Jun 2000, you wrote:
I have now seen over 180 of these scans! 60 in the last 24 hours. One thing I have established since my last post is that these do seem to be targetted at us. I have not had anyone else contact me to say that they have seen these and I contacted the network admin of one of the neighbouring class Bs (another NZ university -- we got our addresses at the same time) and they have not seen any of these scans. Whether the targeting is deliberate of not is anyones guess.
There may be a simple explanation. The port "12345" is the 'netbus-server' standard-port. A lot of IRC-"warscripts" scan for these. If your users are a lot on IRC, and they join large channels, especially efnet, undernet, dalnet and ircnet - then they may be automatically scanned for it. -- "Rune Kristian Viken" <rune () trans4media com> <http://arcade.kvinesdal.com> System, Network & Security Administrator. Phone: (+47) 92 85 34 38
Current thread:
- Re: update on scans of tcp 12345 AUSCERT#36349 Rune Kristian Viken (Jun 08)