Attacks on a Subnet of Ulm University during a Weekend

 [Previous Page]  [Contents]  [Next Page]  [Next Chapter]

*June 22nd, morning: A spammer investigates whether our mail server is an open SMTP relay. Open relays allow to distribute spams with increased anonymity and allow to shift a significant part of the load to the relay.
 
*June 22nd, evening: A T-Online user (major dialin service in Germany) scans for FTP servers with open security holes.
 
*June 23rd, noon: Port scan of UDP port 500 (IKE, Internet Key Exchange) coming from an US university.
 
*June 23rd, evening: A DSL user of an US ISP scans for FTP servers with open security holes.
 
*June 24th, afternoon: A dialin user of an ISP in the Netherlands scans for FTP servers which allow to store illegal data.
 
*June 25th, shortly after midnight: A dialin user from France scans for anonymous FTP servers with security holes.
 
*June 25th, early morning: Port scan coming from an US university on TCP port 27374 which is used by several trojans running under Windows.
 
*Miscellaneous: 1726 blocked spams, 2003 pings from external networks and 24 attempts to connect to the WinGate port.
 
*All these attacks came through the firewall of our computing center.
 

 [Previous Page]  [Contents]  [Next Page]  [Next Chapter]
Copyright © 2001, 2002 Andreas Borchert, converted to HTML on April 07, 2002