LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 06-03-2007, 01:41 AM   #1
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Being hammered by an IP belonging to Vrtservers.net


Is anyone else here being bombarded by IP 64.56.65.150?

The reason I ask is that if you put that IP into a web browser, it points to a very suspicious page that appears to be logging questionable activity. In fact, last month, I reported the IP to ISC.sans.org and they stated that they'd help to get the server taken down, as it was positively hammering my public server and hammering my home network. Using links, I perused the logs listed there and there was a TON of IPs listed. It took about 3 weeks for the site to stop pounding my firewalls, but apparently whoever owns that webserver just restored the latest backup because almost immediately, the machine was popped and began scanning again.

Here is a very small snippet of my logs:

May 27 04:52:45 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x08 PREC=0x00 TTL=54 ID=47538 DF PROTO=TCP SPT=60112 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
May 27 05:07:46 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x08 PREC=0x00 TTL=54 ID=41147 DF PROTO=TCP SPT=50682 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
May 27 05:22:46 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x08 PREC=0x00 TTL=54 ID=35161 DF PROTO=TCP SPT=58373 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
May 27 05:37:48 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x08 PREC=0x00 TTL=54 ID=32708 DF PROTO=TCP SPT=55703 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
May 27 05:52:48 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x08 PREC=0x00 TTL=54 ID=28312 DF PROTO=TCP SPT=62717 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
.
.
.
Jun 3 01:33:25 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x10 PREC=0x00 TTL=54 ID=13852 DF PROTO=TCP SPT=57961 DPT=113 WINDOW=65535 RES=0x00 SYN URGP=0
Jun 3 01:34:30 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x10 PREC=0x00 TTL=54 ID=20748 DF PROTO=TCP SPT=56074 DPT=113 WINDOW=65535 RES=0x00 SYN URGP=0
Jun 3 01:35:31 starchild kernel: Blocked hosts violation: IN=eth0 OUT= MAC=fe:fd:40:3e:e7:dc:00:0c:db:f5:90:00:08:00 SRC=64.56.65.150 DST=xxx.xxx.xxx.xxx LEN=64 TOS=0x10 PREC=0x00 TTL=54 ID=23696 DF PROTO=TCP SPT=51647 DPT=113 WINDOW=65535 RES=0x00 SYN URGP=0

I've like 5000 entries in my logs, going back a month. Luckily, the IP isn't hammering my home account this time...yet. Previously, the IP was attempting mysql connections. It is now trying port 80 and 113.

I haven't been able to find much, other than ISC.sans.org's history of abuse reported by few others.

Reading up on Vrtservers.net, it does appear that many people have complained about the owner of the business. Is there a way to get this IP added to a blacklist? whois.sc currently shows that the IP isn't listed at spamhaus.

I'm not so worried, as traffic is being blocked totally. Seeing this in the logs is highly annoying, though, and my worry is that at some point, if this person is persistent, he/she may eventually get in.

Anyone ever dealt with something like this before?

TIA
 
Old 06-03-2007, 11:29 AM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782

Original Poster
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Screw it. This is a good time for me to begin my implementation of LaBrea Tarpit. Consider this issue closed.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Start a program for a user as root, with process belonging to user gnashley Programming 4 03-19-2007 01:58 PM
LXer: How the Net was Lost - the real story behind Net Neutrality LXer Syndicated Linux News 0 06-20-2006 09:33 PM
sendmail getting hammered nmolinos Linux - Networking 4 04-12-2005 07:26 PM
Port 1025 and 53 UDP being hammered with Blackjack dholingw Linux - Security 2 06-11-2004 02:02 AM
Security Warning: These files belonging to packages are modified on the system jmcollin92 Linux - Security 1 12-29-2003 06:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration