Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: possible hack attempt
From: Brian Feeny <signal @ netjam . net>
Date: Fri, 12 Apr 1996 21:16:06 -0500 (CDT)
To: Fire Walls <firewalls @ GreatCircle . Com>

The other day we had something very strange happen:

We are a small ISP, with 32 dialup customers and about 40 inside machines 
on an ethernet.  Our pipe to the internet has a Cisco 2501 on it.

The Cisco is configured to block EVERYTHING coming into our machien 
except pcnfs,www,nntp,pop3,smtp,dns,ftp.  ALL of the R-Commands are disabled 
as well.  Yet, in the logs there was somethign to the effect of:

2 LOGIN FAILURES from big10.metrobbs.com

How is this possbile?  How could they have accessed login?  This error 
message was NOT an ftp error message.  Also we did NOT have source 
routing disabled on the 2501 at the time, however, if they were pulling 
that crap I don't think it would have shown them coming from metrobbs.com.

NOTE: I am NOT talking about "netjam.net".  The domain I am talking about 
it "softdisk.com".  Our router is link.softdisk.com, and our server that 
had the login failures was server1.softdisk.com.

Any ideas? Someone mentioned before something about this possibly being 
an ip fragment attack or something.


-------------------------------------------------------------------------
Brian Feeny		    http://www.netjam.net	signal @
 netjam .
 net
NetJAM Communications	    Network Consulting		(318) 798-9324
UNIX --  Internetworking --  Security --  Programming --  Troubleshooting
PGP Key: finger signal @
 netjam .
 net



Follow-Ups:
Indexed By Date Previous: Re: firewalls-digest V5 #170 -Reply
From: phoenix @ clark . net
Next: Firewalls for SVR3
From: Brian Feeny <signal @ netjam . net>
Indexed By Thread Previous: Re: Flood Attack? Could be client software!
From: "Adam Pingitore" <Adam_Pingitore @ alli . wnyric . org>
Next: Re: possible hack attempt
From: elroy <elroy @ kcsun3 . kcstar . com>

Google
 
Search Internet Search www.greatcircle.com