[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: hacking



inetnum:     192.114.160.0 - 192.114.191.255
netname:     EURONET-BLOCK-2
descr:       Euronet Ltd.
country:     IL
admin-c:     Shlomi Zohar
tech-c:      Shlomi Zohar
changed:     hank@vm.tau.ac.il 970928
source:      RIPE

Looks like Euronet dial up account...


___________________________________
Hetz Ben Hamo
Linux - NoW ThIs Is A GoOd SoLuTiOn
http://www.linux.org


On Sun, 3 Jan 1999, Erez Doron wrote:

> hi
> 
> here are some of my firewall logs:
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.181:22 L=30 S=0x00 I=36404 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.182:5632 L=30 S=0x00 I=36660 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.182:22 L=30 S=0x00 I=36916 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.183:5632 L=30 S=0x00 I=37172 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.183:22 L=30 S=0x00 I=37428 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.184:5632 L=30 S=0x00 I=37684 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.184:22 L=30 S=0x00 I=37940 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.185:5632 L=30 S=0x00 I=38196 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.185:22 L=30 S=0x00 I=38452 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.186:5632 L=30 S=0x00 I=38708 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.186:22 L=30 S=0x00 I=38964 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.187:5632 L=30 S=0x00 I=39220 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.187:22 L=30 S=0x00 I=39476 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.188:5632 L=30 S=0x00 I=39732 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.188:22 L=30 S=0x00 I=39988 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.189:5632 L=30 S=0x00 I=40244 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.189:22 L=30 S=0x00 I=40500 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.190:5632 L=30 S=0x00 I=40756 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.190:22 L=30 S=0x00 I=41012 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.191:5632 L=30 S=0x00 I=41268 F=0x0000
> T=125
> Jan  3 10:37:37 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1029 192.114.175.191:22 L=30 S=0x00 I=41524 F=0x0000
> T=125
> Jan  3 10:38:44 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1032 192.114.175.128:5632 L=30 S=0x00 I=7992 F=0x0000
> T=125
> Jan  3 10:38:44 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1032 192.114.175.128:22 L=30 S=0x00 I=8248 F=0x0000 T=125
> Jan  3 10:38:44 aristo kernel: IP fw-in deny frame0 UDP
> 192.114.175.50:1032 192.114.175.129:5632 L=30 S=0x00 I=8504 F=0x0000
> T=125
> 
> 
> what kind of attack is this ?
> 
> queso gives: 
> 
> # queso 192.114.175.50
> 192.114.175.50:80       * Not Listen, Windoze 95/98/NT
> 
> 
> I tried to Nuke them ('nuke 192.114.175.50') but this has no effect
> 
> (and they continue to probe me ...)
> 
> any Idea how can I kill an MS box ?
> 
> regards
> erez
> 
> p.s. internet zahav wouldn't tell me who it is, and wouldent warn himn
> either
> unless i complain at the police.
>