Hi folks, I am seeing an IPv6-connected host on my network (which is on a HE.net tunnel) apparently being portscanned by an HE server at 2001:470:0:64::2 for about the last hour or so. It is trying to hit several different ports four times each before moving on and eventually repeating itself. If anyone from HE can shed some light on what's going on here it would be greatly appreciated, I can provide the IP of the host in question off-list if needed. Thanks, -- Ben
On 12/23/2012 12:31 AM, Ben Carleton wrote:
Hi folks,
I am seeing an IPv6-connected host on my network (which is on a HE.net tunnel) apparently being portscanned by an HE server at 2001:470:0:64::2 for about the last hour or so. It is trying to hit several different ports four times each before moving on and eventually repeating itself.
If anyone from HE can shed some light on what's going on here it would be greatly appreciated, I can provide the IP of the host in question off-list if needed.
Thanks, -- Ben
Thank you to everyone who responded on and off-list, we've got this resolved. -- Ben
Can I ask why you count a port scan at something bad? Or is it just the length of time it has been running for and it re-running the same scan repetitively? ฤ๊๊๊๊๊็็็็็๊๊๊๊๊็็็็ ฮ้้้้้้้้้้้้้้้้้้้้้้้้้้้้้ ฦ้้้้้็็็็็้้้้้็็็็็้้้้้้้้็ On 23 December 2012 05:31, Ben Carleton <ben@bencarleton.com> wrote:
Hi folks,
I am seeing an IPv6-connected host on my network (which is on a HE.net tunnel) apparently being portscanned by an HE server at 2001:470:0:64::2 for about the last hour or so. It is trying to hit several different ports four times each before moving on and eventually repeating itself.
If anyone from HE can shed some light on what's going on here it would be greatly appreciated, I can provide the IP of the host in question off-list if needed.
Thanks, -- Ben
-- BaconZombie LOAD "*",8,1
Be aware.. There have been reports of bacon zombies port scanning lately.
From my Galaxy Note II, please excuse any mistakes.
-------- Original message -------- From: Bacon Zombie <baconzombie@gmail.com> Date: 12/23/2012 3:20 PM (GMT-07:00) To: Cc: nanog@nanog.org Subject: Re: Hurricane Electric Tunnelbroker staff? Can I ask why you count a port scan at something bad? Or is it just the length of time it has been running for and it re-running the same scan repetitively? �������������������� ������������������������������ ������������������������������ On 23 December 2012 05:31, Ben Carleton <ben@bencarleton.com> wrote:
Hi folks,
I am seeing an IPv6-connected host on my network (which is on a HE.net tunnel) apparently being portscanned by an HE server at 2001:470:0:64::2 for about the last hour or so. It is trying to hit several different ports four times each before moving on and eventually repeating itself.
If anyone from HE can shed some light on what's going on here it would be greatly appreciated, I can provide the IP of the host in question off-list if needed.
Thanks, -- Ben
-- BaconZombie LOAD "*",8,1
participants (3)
-
Bacon Zombie
-
Ben Carleton
-
Warren Bailey