[Dshield] Kornet.Net

Tony Carothers tony.carothers at lifestreamtech.com
Wed Mar 6 15:37:43 GMT 2002


I have 211.104.xxx.xxx though 211.119.xxx.xxx as well.  Seems to take
another chunk of port scans off as well.

-----Original Message-----
From: Grant Thurman [mailto:Grant at Netprecision.Net]
Sent: Tuesday, March 05, 2002 5:07 PM
To: list at dshield.org
Subject: [Dshield] Kornet.Net


Brian Burrington,

I have blocked the following with good success, and don't feel we have lost
much in the process, I will always be redefining my list but the firewall
alerts have dropped way off by fine tuning my port blocking and blocking the
following:

210.52.76.0 -> 210.52.77.255 China (Bulk of the hacking seems to come from
this IP block)

211.51.0.0  -> 211.51.255.255 Korea (Bulk of the hacking seems to come from
this IP block)

193.204.0.0 -> 193.204.0.255 Italy (Yep, they kept banging away at me)

202.0.0.0   -> 203.255.255.255  Apnic  (Bulk of the hacking seems to come
from this IP block)

I get some 64.????? hacking but the IP blocks are all over the board, mine
even starts with 64. as well as our servers at the California, Cox.Net
commercial data center and I can't seem to get a handle on the range the
hackers are coming in on.

Good luck...

===============================
Grant Thurman
Netprecision, Inc.
714.832.8932 Cell: 714.813.3690
===============================

_______________________________________________
Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:
http://www1.dshield.org/mailman/listinfo/list




More information about the list mailing list