[Dshield] These kind of attcks from 127.0.0.1 seems to be a REAL ATTCK

Babak Memari memari at myrealbox.com
Thu Feb 19 18:27:59 GMT 2004


These attcks from 127.0.0.1 seems to be a REAL ATTCK .
And they are not firewalls-errors .
Why?

7:00:53 PM    201.128.78.154    UDP (1026)
6:31:40 PM    80.254.105.146    TCP (12346)
6:31:04 PM    216.155.193.166    TCP (4085)
6:30:35 PM    80.14.5.135    TCP (80)
6:28:24 PM    127.0.0.1    TCP (1135)
6:27:06 PM    195.219.186.127    TCP (1178)
6:24:21 PM    216.155.193.128    TCP (3655)
6:23:19 PM    216.155.193.128    TCP (3655)
5:15:29 PM    199.106.234.122    TCP (3043)
5:15:21 PM    216.155.193.158    TCP (3099)
5:15:13 PM    128.121.26.136    TCP (3148)
5:15:01 PM    66.35.229.207    TCP (3146)
5:14:25 PM    199.106.234.122    TCP (3043)
5:14:18 PM    216.155.193.158    TCP (3099)
5:14:09 PM    128.121.26.136    TCP (3148)
2:11:15 PM    127.0.0.1    TCP (1556)
2:11:11 PM    80.253.226.174    TCP (1066)

I think that these attcks from 127.0.0.1 seems to be a REAL ATTCK .
Because whenever I  see these attcks from 127.0.0.1 , I  am not
able to use PROXY_TUNNELING_SOFTWARES such as
http://www.htthost.com/  or  www.hopster.com  for changing my IP .
These softwares use LOOPBACK ( 127.0.0.1 )  .

Your idea?
-----
Babak from Earth
www.voidspace.org.uk/babak






More information about the list mailing list