RE: odd worm (?) activity?
"Bill Royds" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Some address spaces overlap on the same physical subnet. My IP is in 69.198/16, but it shares physical LAN (cable head end) with 24.157/16. The address depends on the cable modem brand, but sniffing traffic gives both ranges. So other addresses ranges would still be from another system on the same subnet. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Timothy Chase Sent: Tuesday, September 14, 2004 11:03 AM To: Intrusions List (GCIA Practicals) Subject: Re: [Intrusions] odd worm (?) activity? Charlie, You stated, > ... > There are more duplicated ports than just 135. And all of the ports > are common worm backdoor ports. Also, since the scan is sourced from > another system on the same subnet, it is likely that the "scanner" is > unaware of the infection. I hope you don't mind, but I was wondering why being on the same subnet suggests that the "scanner" is unaware of the infection? For example, it has been my experience that virtually all attempts by bots to make use of the Bagle backdoor are from the same subnet (24), although recently, I have seen a few attempting to come in from the 60's and 200's (I would have to check my logs to give you the exact subnet or ip address), and only afterwards did I see any which (when ftp'd over) had the same md5-hashes from my own subnet. Are connection attempts by bots from other subnets indicative of seeding, as the phenoma I have observed would seem to indicate, and if so, why? Tim _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions