AmigaActive (1355/1728)

From:Andy Wanless
Date:25 Jun 2001 at 23:47:32
Subject:Re: Internet Abuse and Port Hacks (reply)

25/06/01 23:20:34, Craig_Daines@excite.co.uk wrote:
>
>Well, ports are opening even if a server running on them: here is an
>example of an illegal port attack which occured 2nite.
>
>Access from host 211.162.94.1 to port tcp/111 allowed.
>
>Lookup Enquiry of service port 111 reveals:-
>TCP--sunrpc portmapper. Sun Remote Procedure Call/Portmapper.

Ah, that port. You'll get attempts to connect to that all the time, standard
script kiddy attack. You'll also get attempts to connect to various other ports,
such as telnet and ftp ports, and possibly things like IMAP and POP3 (can't
remember the numbers).

It's not worth worrying about these things, really. If you've not got anything
doing anything with that port, there's not really anything anyone can do. It's
just someone scanning various ports to see what your machine is and how they
can abuse it.

>From various attempts at keeping annoying script kiddies out of Linux servers for
work, if you're not allowing telnet or ftp (ports 21 and 23?), you're pretty safe.

So don't worry about random port scans, you're going to get them anyway. Is
a handful of bytes every so often really worth the effort of complaining to someone's
ISP? Not much they'll do about it unless it's a much more sustained attack. You'll
only be wasting their time when they could be dealing with much more important
and expensive attacks. (Can anyone guess what happened to a server I'm
allegedly in charge of recently? ;)

Quote carefully and read all ADMIN:README mails
To unsubscribe mailto:amigactive-unsubscribe@yahoogroups.com
Anyone sending unsubscribe messages to the list will be SHOT!

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/