Re: [Hampshire] Router secuity alerts

Top Page
Author: Brad Rogers
Date:  
To: hampshire
Subject: Re: [Hampshire] Router secuity alerts

Reply to this message
gpg: failed to create temporary file '/var/lib/lurker/.#lk0x57dd8100.hantslug.org.uk.9385': Permission denied
gpg: keyblock resource '/var/lib/lurker/pubring.gpg': Permission denied
gpg: Signature made Wed May 13 12:52:21 2009 BST
gpg: using RSA key 4BC36C6C174D31C1
gpg: Can't check signature: No public key
On Wed, 13 May 2009 12:22:01 +0100
Clive Woodfine <clivewoodfine@???> wrote:

Hello Clive,

> TCP Packet - Source:61.139.105.163 Destination:89.242.150.73 - [PORT
> SCAN]


I've received similar warnings recently, too. Similar router; v2 rather
than v3. They continued for about a week and then stopped. I suspect a
machine has been set up to attack weak systems, with the intent of
adding them (unknown to the owner of course) to an email farm, or
somesuch. When it gets no success, it moves on to the next block.

If you haven't altered the router's default settings for inbound
services (i.e. block everything), you're probably safe. If you've got a
web, mail or any other server running, you might want to check they're
okay.

Keep an eye on the usage graphs your ISP has for your connection; A
sudden rise in activity _might_ mean a compromised system.

-- 
 Regards  _
         / )           "The blindingly obvious is
        / _)rad        never immediately apparent"


What will you do when the gas taps turn?
The Gasman Cometh - Crass