Hej
I min boligforening deles vi om 2 adsl linier fra Tiscali.
Jeg har netop modtaget nedenstående mail fra deres abuse-afdeling:
----- Original Message -----
From: "Tiscali A/S - AbuseTeam" <abuse@tiscali.dk>
To: bleh_niklas@it.edu
Sent: Monday, January 19, 2004 9:52 AM
Subject: Re: Analyzer Incident Notification for IP Address 62.79.98.131
(PR#42358)
> Hej,
>
> Vi har modtaget en henvendelse, som har gjort os opmærksom på, at
vedkommende er
> blevet port scannet fra Jeres forbindelse.
>
> Vi opfordrer Jer på det kraftigste til at stoppe disse aktiviteter
> øjeblikkeligt, det skal nævnes at disse aktiviteter godt kan skyldes en
> virus-infektion på Jeres maskine(r). Af netop samme årsag vil jeg anbefale
Jer
> at få kontrolleret al edb for virus.
>
> Hvis disse aktiviteter fortsat finder sted, vil Tiscali se sig nødsaget
til at
> blokere netforbindelsen til nævnte ting er bragt til ende.
>
> > You have received this notice because a network under your
administrative
> > control was the origin of network attacks or suspicious activity. This
is
> > a notification from the Symantec DeepSight Analyzer service. DeepSight
> > Analyzer is an online service that allows users to identify, track, and
> > respond to security events that have been reported by their Intrusion
> > Detection and Firewall systems. This notification that you have
received,
> > which is one function of this service, allows users to submit records of
> > these security events to the domain contact and Internet Service
Provider
> > from where the activity originated. This notification allows you to
> > respond to the use of your network as the origin of attacks, preventing
> > future attacks against individuals, businesses and other potential
> > targets. This email has been sent by an automated system.
> >
> > Users of DeepSight Analyzer provide the text that follows. While
Symantec
> > developed and administers DeepSight Analyzer, Symantec does not take any
> > responsibility for the accuracy or legitimacy of this notification or
any
> > of the information held therein. The individual making this notification
> > has supplied any and all information; therefore the information provided
> > in this notification is the responsibility of that individual alone.
> > Symantec does not bear any responsibility or assume any liability for
the
> > information and comments that follow.
> >
> > stop attacking my computer
> >
> > This same system also attacked 4 other ARIS system users.
> >
> > Attack Summary
> >
> >
> >
> > NOTE all times in UTC
> >
> > Jan 8 2004 3:57:20:000PM - Generic Connection Denied Event
> > 62.79.98.131 -> 0.0.0.0 <4662-4662> TCP
> >
> > Jan 8 2004 3:57:08:000PM - Generic Connection Denied Event
> > 62.79.98.131 -> 0.0.0.0 <4662-4662> TCP
> >
> > Jan 8 2004 3:57:02:000PM - Generic Connection Denied Event
> > 62.79.98.131 -> 0.0.0.0 <4662-4662> TCP
> >
> > Jan 8 2004 3:56:59:000PM - Generic Connection Denied Event
> > 62.79.98.131 -> 0.0.0.0 <4662-4662> TCP
> >
> > Generic Connection Denied Event
> > This event indicates that an incoming connection has been denied. The
> > protocol variable may either be TCP, UDP, or ICMP.
> >
> > The data provided in this notification is collected from Intrusion
> > Detection and Firewall systems. While these products are highly
> > effective, they are prone to false positives, and the attacks that are
> > reported may be a result of legitimate traffic. Symantec strongly
> > recommends that the recipient of this notification take the appropriate
> > steps to confirm the legitimacy of this alert. Symantec takes no
> > responsibility for the accuracy or legitimacy of this notification, nor
> > does it take any responsibility or bear any liability for the actions
> > taken by the recipient pursuant to receipt of this notification. If this
> > email has reached you in error, please contact analyzer@symantec.com so
> > that we can correct our contact information. To learn more about
> > DeepSight Analyzer please visit
http://analyzer.symantec.com.
> >
> > --
> Med Venlig Hilsen / Kind Regards
> Mikkel Wied, Tiscali A/S, Abuse Team
> Lautrupsgade 9, DK-2100 København Ø -
www.tiscali.dk
> Telefon +45 3814 7000, Fax +45 3814 7007
>
Så vidt jeg kan se, er der tale om at en maskine fra vores netværk har
forsøgt at forbinde til 4 maskiner på port 4662.
Jeg ved ikke hvilke adresser der er blevet "angrebet", så det er lidt svært
at vurdere om forsøgene på at skabe forbindelse havde et legitimt formål.
Jeg synes dog Tiscali er lidt hurtige til at give klageren ret og betegne
ovenstående som portscanning eller angreb.
Mvh,
Niklas Petersen