//flex table opened by JP

Click to See Complete Forum and Search --> : Chinese are active tonight!!


sharder8
08-14-2001, 10:26 PM
My firewall has blocked 8 pings in the last 2 hours! Most weren't very serious, but this one hit twice, an hour apart!

inetnum: 61.139.128.0 - 61.139.191.255
netname: CHINANET-JL
descr: CHINANET Jilin province network
descr: Data Communication Division
descr: China Telecom
country: CN
admin-c: CH93-AP
tech-c: XY1-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINANET-JL
changed: hostmaster@ns.chinanet.cn.net 20010120
source: APNIC person: Chinanet Hostmaster
address: A12,Xin-Jie-Kou-Wai Street
country: CN
phone: +86-10-62370437
fax-no: +86-10-62053995
e-mail: hostmaster@ns.chinanet.cn.net
nic-hdl: CH93-AP
mnt-by: MAINT-CHINANET
changed: hostmaster@ns.chinanet.cn.net 20000101
source: APNIC person: Xu Yongzhong
address: Data Communication Bireau
address: Ministry of Posts and Telecommunications
address: A12 Xin-jie-kou-wai Street
address: Beijing 100088
country: CN
phone: +86-10-62053991
fax-no: +86-10-62053995
e-mail: yzxu@publicf.bta.net.cn
nic-hdl: XY1-AP
mnt-by: MAINT-NULL

Anyone else getting hit by these guys tonight?

UPDATE

This one has hit 4 times in last 3 hours! http://www.sysopt.com/forum/frown.gif

inetnum: 203.66.0.0 - 203.66.255.255
netname: HINET-TW
descr: CHTD, Chunghwa Telecom Co.,Ltd.
descr: Data-Bldg.6F, No.21, Sec.21, Hsin-Yi Rd.
descr: Taipei Taiwan 100
country: TW
admin-c: HN27-AP
tech-c: HN28-AP
remarks: This information has been partially mirrored by APNIC from
remarks: TWNIC. To obtain more specific information, please use the
remarks: TWNIC whois server at whois.twnic.net.
mnt-by: TWNIC-AP
changed: hostmaster@twnic.net 19960212
source: APNIC person: HINET Network-Adm
address: CHTD, Chunghwa Telecom Co., Ltd.
address: Data-Bldg. 6F, No. 21, Sec. 21, Hsin-Yi Rd.,
address: Taipei Taiwan 100
country: TW
phone: +886 2 2322 3495
phone: +886 2 2322 3442
phone: +886 2 2344 3007
fax-no: +886 2 2344 2513
fax-no: +886 2 2395 5671
e-mail: network-adm@hinet.net
nic-hdl: HN27-AP
remarks: same as TWNIC nic-handle HN184-TW
mnt-by: TWNIC-AP
changed: hostmaster@twnic.net 20000721
source: APNIC person: HINET Network-Center
address: CHTD, Chunghwa Telecom Co., Ltd.
address: Data-Bldg. 6F, No. 21, Sec. 21, Hsin-Yi Rd.,
address: Taipei Taiwan 100
country: TW
phone: +886 2 2322 3495
phone: +886 2 2322 3442
phone: +886 2 2344 3007
fax-no: +886 2 2344 2513
fax-no: +886 2 2395 5671
e-mail: network-center@hinet.net
nic-hdl: HN28-AP
remarks: same as TWNIC nic-handle HN185-TW
mnt-by: TWNIC-AP

[This message has been edited by sharder8 (edited 08-14-2001).]

smokin1
08-14-2001, 11:43 PM
No big deal..as long as your "firewall" is shedding the scans..they are scanning known cable IP's..and almost every web server with IIS installed. On another note..my own ISP DOS'sed me off the net..had to reboot my dratted router for the first time in ages...notice how slow the net is lately?..something is going on..and we are being treated as mushrooms..
http://www.sysopt.com/forum/frown.gif

club_med
08-15-2001, 03:41 AM
Its a conspiracy !!!

http://www.sysopt.com/forum/wink.gif

Philip1952
08-15-2001, 06:04 AM
I have been getting hit from those ip's also. About 6 to 8 times a day. I'm on a 56k hook also. I have been getting it from these ip's for better than a week now.
A few people I work with have the same ip scans also. They are on different isp's with different range of ip address also.

daveleau
08-15-2001, 07:08 AM
Moved to the networking forum

Have a good one
Dave