[H-GEN] Router Intrusion?

Snowy Angelique Maslov aka 'Snowpony' snowy at snowy.org
Mon Oct 6 02:16:46 EDT 2003


[ Humbug *General* list - semi-serious discussions about Humbug and     ]
[ Unix-related topics. Posts from non-subscribed addresses will vanish. ]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, 6 Oct 2003, Conor Cunningham wrote:

> I give my permission to people on this list to do a security scan on my 
> machine, if they think it would be of any use for informative purposes. I 
> am a bit lost at the moment, so any advice would be great.
> 
> My IP is 210.49.33.240.

Basic nmap scan seems to show nothing open on the outside at least.

[/u01/home/snowy]$ sudo nmap -sT -O -vv -P0 210.49.33.240

Starting nmap V. 3.00 ( www.insecure.org/nmap/ )
Host c210-49-33-240.fitzg1.qld.optusnet.com.au (210.49.33.240) appears to be 
up ... good.
Initiating Connect() Scan against c210-49-33-240.fitzg1.qld.optusnet.com.au 
(210.49.33.240)
RTTVAR has grown to over 2.3 seconds, decreasing to 2.0
The Connect() Scan took 2403 seconds to scan 1601 ports.
Warning:  OS detection will be MUCH less reliable because we did not find at 
least 1 open and 1 closed TCP port
All 1601 scanned ports on c210-49-33-240.fitzg1.qld.optusnet.com.au 
(210.49.33.240) are: filtered
Too many fingerprints match this host for me to give an accurate OS guess
TCP/IP fingerprint:
SInfo(V=3.00%P=i386-redhat-linux-gnu%D=10/6%Time=3F810207%O=-1%C=-1)
T5(Resp=N)
T6(Resp=N)
T7(Resp=N)
PU(Resp=N)



Nmap run completed -- 1 IP address (1 host up) scanned in 2794 seconds

- -- 
Snowy "Snowpony" Angelique Cerise Maslov -- http://snowy.org/email.signature
PGP (GnuPG) fingerprint = 5280 6EBC D281 A9D2 564B  E274 B2EC 54C3 8325 CECD
Email not addressed/CCd to snowy at snowy.org BOUNCE.  READ URL for disclaimer!
   "Ignorance killed the cat, sir. Curiosity was framed." ---C.J. Cherryh
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: For info see http://quantumlab.net/pine_privacy_guard/

iD8DBQE/gQjOsuxUw4Mlzs0RAsOUAJ9L8bm9U4dbwNbsWH7itBfBNAf/qQCdH/zT
oVyfSc6CofmcPE6kEY9Kf74=
=bhAO
-----END PGP SIGNATURE-----


--
* This is list (humbug) general handled by majordomo at lists.humbug.org.au .
* Postings to this list are only accepted from subscribed addresses of
* lists 'general' or 'general-post'.  See http://www.humbug.org.au/



More information about the General mailing list