nanog mailing list archives

Re: Hurricane Electric Tunnelbroker staff?


From: Warren Bailey <wbailey () satelliteintelligencegroup com>
Date: Sun, 23 Dec 2012 23:32:31 +0000

Be aware.. There have been reports of bacon zombies port scanning lately.


From my Galaxy Note II, please excuse any mistakes.


-------- Original message --------
From: Bacon Zombie <baconzombie () gmail com>
Date: 12/23/2012 3:20 PM (GMT-07:00)
To:
Cc: nanog () nanog org
Subject: Re: Hurricane Electric Tunnelbroker staff?


Can I ask why you count a port scan at something bad?
Or is it just the length of time it has been running for and it re-running
the same scan repetitively?



ฤ๊๊๊๊๊็็็็็๊๊๊๊๊็็็็ ฮ้้้้้้้้้้้้้้้้้้้้้้้้้้้้้
ฦ้้้้้็็็็็้้้้้็็็็็้้้้้้้้็


On 23 December 2012 05:31, Ben Carleton <ben () bencarleton com> wrote:

Hi folks,

I am seeing an IPv6-connected host on my network (which is on a HE.net
tunnel) apparently being portscanned by an HE server at 2001:470:0:64::2
for about the last hour or so. It is trying to hit several different ports
four times each before moving on and eventually repeating itself.

If anyone from HE can shed some light on what's going on here it would be
greatly appreciated, I can provide the IP of the host in question off-list
if needed.

Thanks,
-- Ben




--


BaconZombie

LOAD "*",8,1


Current thread: