BLOGS
The Channel Wire
June 22, 2009
The activity logs in the Test Center's Honeypot Test Network were surprisingly quiet this weekend. The expectation was for a possible increase in spam, especially in light of all of the political unrest in Iran and an assassination attempt of a Russian leader.

Activity logs show packet sniffs coming from a number of IPs that geo-locate back to providers in China and Korea. Packet sniffs often are likened to wiretapping of phones, except in this case it is a data network getting "tapped." Packet sniffing is used by hackers to garner all kinds of information about a network.

Activity also was logged against Terminal Services port 3436 from an IP address that traces to Paris. A reverse DNS lookup shows the domain is abo.wanadoo.fr.

There also were a few SQL Server UDP Worm attacks from IP addresses that appear to be coming from Japan and China.

Also logged were several attempts to send crafted ICMP echo requests coming from an IP address from the New York area from Verizon's FIOS network. These types of requests often are used by hackers for host detection or to fingerprint a remote machine's operating system.

Posted by Samara Lynn at 1:25 PM
Media Kits | Reprints | Privacy Statement | Copyright © 2010 United Business Media LLC | Terms of Service
CRN Logo ChannelWeb Logo CRN Logo CRNTech Logo Everything Channel Events IPED
ADVERTISEMENT




CHANNEL SERVICES >>