LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-16-2005, 03:03 PM   #1
Pauli
Member
 
Registered: Feb 2004
Location: Montreal
Distribution: Gentoo/Debian
Posts: 365

Rep: Reputation: 30
IBM Port scanning?


Somebody port scanned me on ports 33463, 33464, 33465, and 33467 and an instant later somebody scanned 33459, 33460, 33461, and 33463

170.224.176.50
170.224.176.49

From these two IP's. I backtraced them and it tells me its IBM.


OrgName: IBM
OrgID: IBM-1
Address: IBM Raleigh - IP Services Team
Address: 3039 Cornwallis Road
City: Reserach Triangle Park
StateProv: NC
PostalCode: 27709-2195
Country: US

NetRange: 170.224.0.0 - 170.227.255.255
CIDR: 170.224.0.0/14
NetName: IBM-COMMERCIAL
NetHandle: NET-170-224-0-0-1
Parent: NET-170-0-0-0-0
NetType: Direct Assignment
NameServer: RTPUSSXDNSB03.RALEIGH.MEBS.IHOST.COM
NameServer: RTPUSSXDNSB04.RALEIGH.MEBS.IHOST.COM
NameServer: BLDUSWXDNSB01.BOULDER.MEBS.IHOST.COM
NameServer: BLDUSWXDNSB02.BOULDER.MEBS.IHOST.COM
Comment:
RegDate: 1995-04-21
Updated: 2005-06-03

OrgTechHandle: NOCTE3-ARIN
OrgTechName: NOC Team
OrgTechPhone: +1-999-999-9999
OrgTechEmail: noc@ibm.com


Why in hell would someone from IBM be port scanning me? Then my firewall blocked out traffic from both IP's for 600 seconds.

I'm just kind of curious, it seems as if someone tried to do a bad attack, but from IBM?? What do you think it is?
 
Old 08-16-2005, 03:31 PM   #2
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
/me coughs ...

You're running some instant messaging clients?
Chat with people who may be working at IBM?


Cheers,
Tink
 
Old 08-16-2005, 03:43 PM   #3
Pauli
Member
 
Registered: Feb 2004
Location: Montreal
Distribution: Gentoo/Debian
Posts: 365

Original Poster
Rep: Reputation: 30
AFAIK noone I know works at IBM
 
Old 08-16-2005, 04:02 PM   #4
Vgui
Member
 
Registered: Apr 2005
Location: Canada
Distribution: Slackware
Posts: 496

Rep: Reputation: 31
Just a normal home computer? Or are you running a webserver or something along those lines?
IBM did announce they would be releasing an open source search engine of sorts, so maybe they are trying to index you (if you are running a webserver, etc.)
*shrugs* I wouldn't get too hot and bothered though.
 
Old 08-16-2005, 04:52 PM   #5
SteveK1979
Member
 
Registered: Feb 2004
Location: UK
Distribution: RHEL, Ubuntu, Solaris 11, NetBSD, OpenBSD
Posts: 225

Rep: Reputation: 43
Except for the fact that webservers being indexed by search engines usually happens on port 80.....
 
Old 08-16-2005, 05:01 PM   #6
Vgui
Member
 
Registered: Apr 2005
Location: Canada
Distribution: Slackware
Posts: 496

Rep: Reputation: 31
*shrugs*
Maybe they got confused?
 
Old 12-09-2005, 08:58 AM   #7
kedidie
LQ Newbie
 
Registered: Dec 2005
Posts: 8

Rep: Reputation: 0
got the same problem

i've got the same problem
being portscanned by those two ip's
I've did some homework and I've got the mac address of the atacker
00-30-B8-C1-78-01
anyone who knows what to do?
I don't know what happened
greetz
 
Old 12-09-2005, 09:13 AM   #8
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Quote:
Originally Posted by Pauli
Somebody port scanned me on ports 33463, 33464, 33465, and 33467 and an instant later somebody scanned 33459, 33460, 33461, and 33463

170.224.176.50
170.224.176.49
What do you think it is?
TCP, UDP ?
TTL?

Could be a traceroute
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Port scanning? muppski Linux - Security 6 07-01-2005 05:44 PM
Is my box port scanning? ryedunn Linux - Security 2 01-07-2005 04:45 AM
Smart Port Scanning? Half_Elf Linux - Security 1 01-25-2002 11:28 PM
port scanning johncla Linux - Networking 1 05-02-2001 03:09 AM
Port Scanning tfrye Linux - Security 2 03-24-2001 09:43 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:17 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration