[Dshield] massive scans on

k.lichtenwalder@computer.org k.lichtenwalder at computer.org
Tue Aug 7 21:13:01 GMT 2001

security at admin.fulgan.com schrieb:
> That means that either the attacker is local or someone is not doing
> his job configuring routers: this is global broadcasts and it

I guess it's the second thing. It's the external interface and honestly,
I don't trust the ISP involved not that much. I do have a second system
with another ISP, with about 30 webservers active in a full /24 net,
with the same fw rules, and I don't see those addresses, not because
they could be from an internal network but because that ISP is much more

> shouldn't be able to cross routers. In fact, it's disabled by default
> on all routers that I know of.

Yeah, right, see above... Also, I'd wager, they use source routing,
which is disabled on that system also...
> Now, given the fact that it seems to be coming from several IPs, with
> port 80, I would think that the problem is your log file. Perhaps it's
> confusing "subnet broadcasts" (that's packets sent to the broadcast
> address of your network) with global broadcasts (the all-network
> broadcast The former is generated by CodeRed random
> IP generator and WILL cross routers (although, a well-behaved and
> firewalled router will not carry local broadcasts)
Well, it's indeed all-network broadcast. And it's coming from external.
But it looks like I should take that to the ISP involved...

