[HECnet] 108.31.82.9/QCOCAL

Jordi Guillaumes i Pons jg at jordi.guillaumes.name
Wed Jun 22 04:02:41 PDT 2016


> El 20 juny 2016, a les 20:14, Brian Schenkenberger, VAXman- <system at TMESIS.COM> va escriure:
> 
> 108.31.82.9.

Uh, I’d bet the simulated 3900 is not the real origin of the attack you are getting. It is probably behind a home DSL/cable router, whith port 23 redirected to the 3900’, which has probably a private IP address masqueraded using NAT… So probably the node owner has been hacked and zombified, regadrless of he having a pet 3900 open to the net.

Anyway, it would be good to send a heads up to the operator. I can’t see any QCOCAL node in HECNET, so I don’t know ho he is.

J.




More information about the Hecnet-list mailing list