[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[connect24h:02105] portscan でしょうか



◆ こんなあなたに役立つサイトです!                ◆
◆◆ 【『あなた』の条件】                    ◆◆
◆◆◆  ●IT、印刷、経理、、、会社で業務の外注先を探している ◆◆◆
◆◆   ●いちいち電話で探したりの面倒な作業は避けたい     ◆◆
◆      click!⇒ http://business.rakuten.co.jp        ◆
------------------------------------------------------------------------


古山@姫路です。

フレッツ ISDN でほぼ常時接続しているのですが、最近の ipfilter の log に
各ポートをスキャンしていったような痕跡があるのですが、今回の場合、国は違
うけど同じ ISP の管理しているアドレスから来ているのがおもしろいかなと。

最近、セキュリティについて勉強しはじめたところなので必要な情報か、そうで
無いのかの判断がついていませんので、不必要な情報でしたらごめんなさい。
周りに詳しい人が一人もいないので本と ml が情報源なもので。

-- ipfilter block log --
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1842 -> myaddress,smtp PR tcp len 20 44 -S IN
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1843 -> myaddress,finger PR tcp len 20 44 -S IN
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1844 -> myaddress,tacnews PR tcp len 20 44 -S IN
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1845 -> myaddress,pop3 PR tcp len 20 44 -S IN
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1846 -> myaddress,printer PR tcp len 20 44 -S IN
11/03 23:32:56 tun0 b hoge.wanadoo.nl,1847 -> myaddress,3128 PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1840 -> myaddress,ftp PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1845 -> myaddress,pop3 PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1841 -> myaddress,telnet PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1843 -> myaddress,finger PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1847 -> myaddress,3128 PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1842 -> myaddress,smtp PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1844 -> myaddress,tacnews PR tcp len 20 44 -S IN
11/03 23:33:00 tun0 b hoge.wanadoo.nl,1846 -> myaddress,printer PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1840 -> myaddress,ftp PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1845 -> myaddress,pop3 PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1841 -> myaddress,telnet PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1843 -> myaddress,finger PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1847 -> myaddress,3128 PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1842 -> myaddress,smtp PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1844 -> myaddress,tacnews PR tcp len 20 44 -S IN
11/03 23:33:05 tun0 b hoge.wanadoo.nl,1846 -> myaddress,printer PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1840 -> myaddress,ftp PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1845 -> myaddress,pop3 PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1841 -> myaddress,telnet PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1843 -> myaddress,finger PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1847 -> myaddress,3128 PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1842 -> myaddress,smtp PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1844 -> myaddress,tacnews PR tcp len 20 44 -S IN
11/03 23:33:17 tun0 b hoge.wanadoo.nl,1846 -> myaddress,printer PR tcp len 20 44 -S IN

13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,pop3 PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,smtp PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,printer PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:46 tun0 b huga.wanadoo.fr,47765 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,pop3 PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,smtp PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,printer PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:48 tun0 b huga.wanadoo.fr,47766 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,pop3 PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,smtp PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,printer PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:49 tun0 b huga.wanadoo.fr,47767 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,printer PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,smtp PR tcp len 20 40 -S IN
13/03 11:43:51 tun0 b huga.wanadoo.fr,47768 -> myaddress,pop3 PR tcp len 20 40 -S IN
13/03 11:43:52 tun0 b huga.wanadoo.fr,47769 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:52 tun0 b huga.wanadoo.fr,47769 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:52 tun0 b huga.wanadoo.fr,47769 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:52 tun0 b huga.wanadoo.fr,47769 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:53 tun0 b huga.wanadoo.fr,47769 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:53 tun0 b huga.wanadoo.fr,47769 -> myaddress,printer PR tcp len 20 40 -S IN
13/03 11:43:53 tun0 b huga.wanadoo.fr,47769 -> myaddress,smtp PR tcp len 20 40 -S IN
13/03 11:43:53 tun0 b huga.wanadoo.fr,47769 -> myaddress,pop3 PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,telnet PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,finger PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,tacnews PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,ftp PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,domain PR tcp len 20 40 -S IN
13/03 11:43:54 tun0 b huga.wanadoo.fr,47770 -> myaddress,pop3 PR tcp len 20 40 -S IN

-- ends here --

--
 akitada koyama
   cx2@xxxxxxxxxxxx