2011-09-22
A real IPv6 portscan!
Sep 22 10:55:34 g ...
A real IPv6 portscan!Sep 22 10:55:34 greenblatt kernel: [3664265.488791] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=52215 DPT=1025 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 10:55:34 greenblatt kernel: [3664265.488874] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=48673 DPT=445 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 10:55:34 greenblatt kernel: [3664265.500075] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=49612 DPT=3306 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 10:55:34 greenblatt kernel: [3664265.554699] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=44686 DPT=110 WINDOW=12200 RES=0x00 SYN URGP=0 .. Sep 22 11:08:05 greenblatt kernel: [3664584.510834] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=47639 DPT=1801 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 11:08:07 greenblatt kernel: [3664581.057958] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=52005 DPT=301 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 11:08:07 greenblatt kernel: [3664581.078910] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=45484 DPT=7800 WINDOW=12200 RES=0x00 SYN URGP=0 Sep 22 11:08:08 greenblatt kernel: [3664581.282670] FW reject: IN=ppp0 OUT= MAC= SRC=2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 DST=2001:0980:14ca:0042:0000:0000:0000:0694 LEN=80 TC=0 HOPLIMIT=59 FLOWLBL=0 PROTO=TCP SPT=42826 DPT=27356 WINDOW=12200 RES=0x00 SYN URGP=0I wonder which portscanner would use teredo..whois 2001:0000:53aa:064c:3cf9:7720:bc59:4ca0 Querying for the IPv4 endpoint 67.166.179.95 of a Teredo IPv6 address. # American Registry for Internet Numbers NET67 (NET-67-0-0-0-0) 67.0.0.0 - 67.255.255.255 Comcast Cable Communications, Inc. COMCAST (NET-67-160-0-0-1) 67.160.0.0 - 67.191.255.255 Comcast Cable Communications, Inc. CHESTERFIELD-13 (NET-67-166-160-0-1) 67.166.160.0 - 67.166.191.255