<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8518651349466477770</id><updated>2011-11-27T20:11:54.544-05:00</updated><category term='Korea'/><category term='background intelligent transfer service'/><category term='computer security'/><category term='Worm'/><category term='breach'/><category term='atack'/><category term='Patch'/><category term='China'/><category term='honey pot'/><category term='Dorf'/><category term='Zombie'/><category term='security'/><category term='IPS'/><category term='Cyberwar'/><category term='malware'/><category term='attacks'/><category term='attack analysis'/><category term='NCPH'/><category term='infrastructure protection'/><category term='information assurance'/><category term='botnet'/><category term='Cyber security'/><category term='hacker'/><category term='forensics'/><category term='vulnerabilities'/><category term='Intranet'/><category term='information security'/><category term='intrusion'/><category term='Attacking'/><category term='firewall IP'/><category term='compromised systems'/><category term='Taiwan'/><category term='titan rain'/><category term='BITS'/><category term='critical infrastructure protection'/><category term='virus'/><category term='spyware'/><category term='Ecard'/><category term='Update'/><category term='Storm worm'/><category term='DMZ'/><category term='blacoked IP'/><category term='DDOS'/><category term='Thailand'/><category term='probes'/><title type='text'>Cyber Security BLOG</title><subtitle type='html'>The Cyber Security BLOG will highlight "extremely serious" cyber probes and attacks detected in the Black Lab Security Systems Cyber Center.
EXTREMELY SERIOUS RATING: 
(1) Continuous communications (UDP or TCP) being received for more than 4 hours from attacking IP address. 
(2) An attacking IP address that sent communications (TCP, UDP, or RAW) repeatedly within a 12 hour period. Jeffrey Smith jes@blacklabsecurity.com www.blacklabsecurity.com</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>19</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-3131167467248470460</id><published>2007-11-01T23:50:00.000-04:00</published><updated>2007-11-01T23:52:10.832-04:00</updated><title type='text'>Cyber Center Report - November 1, 2007</title><content type='html'>BLSS Cyber Center Report - 1 Nov 2007&lt;br /&gt;-------------------------------------&lt;br /&gt; &lt;a href="http://www.blacklabsecurity.com/"&gt;www.blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;China and Korea are still probing/attacking on all previously reported IPs and Ports with the same tenacity.  There has been no decrease in the frequency of probes/attacks from China or Korea.  However, within the last 24 hour period, we have detected the least number of new computers now broadcasting over the Internet.  Over the past 24 hours, only (approx) 22 new computers have begun to broadcast over the Internet.  It appears that disabling port 7212 does have a significant impact on China/Korea's ability to successfully penetrate a computer.&lt;br /&gt;&lt;br /&gt;Port 1024; U.S. (new site). Port 1026; Korea (new site), U.S. No IANA Probe last night.  This is the first time in several days that the U.S. IANA has NOT probed the Internet on port 1026.  However, we did detect an Internet-wide probe of the "Latin American and Caribbean IP address Regional Registry", which is the equivalent of the U.S. IANA.  We also detected a probe from the "Broadcasting Center Europe S.A." that is located in Luxembourg.  This may be the Luxembourg equivalent to the U.S. IANA. We detected one U.S. DoD computer probing on port 1026.  We detected two computers with no recorded (unknown) IP addresses probing on port 1026 (most likely some government agency computers).  We detected a computer from J.P.&lt;br /&gt;Morgan probing on port 1026.  Other countries probing on port 1026; U.K. (Peat Marwick computer), France (new site), Brazil (new site).  Port 22; China (new site).  Port 1433; U.S. (2 new site), China (2 new sites). Port 1434; Croatia (new site).  Port 2967; U.S. (new site). Port 5900; China (new sites), Chile (new site), Spain (new site), France (new site).  Honey Pot Activity; None. No one surfed or attacked the Honey Pot.&lt;br /&gt;&lt;br /&gt;The following is a list of new IPs detected and their associated ports;&lt;br /&gt;&lt;br /&gt;----Port 1024 -------------&lt;br /&gt;IP Address   : 64.157.15.117 [ yui.desync.com ]&lt;br /&gt;ISP          : Level 3 Communications&lt;br /&gt;Organization : CandidHosting&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Tampa, FL 33602&lt;br /&gt;Latitude     :  27°95'78" North&lt;br /&gt;Longitude    :  82°46'22" West&lt;br /&gt;&lt;br /&gt;----Port 1026 -------------&lt;br /&gt;IP Address   : 211.199.169.161 [ 211.199.169.161 ]&lt;br /&gt;ISP          : KRNIC&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  37°00'00" North&lt;br /&gt;Longitude    : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 146.220.130.21 [ dummy.clt-ufa.net ]&lt;br /&gt;ISP          : Broadcasting Center Europe S.A.&lt;br /&gt;Organization : Broadcasting Center Europe S.A.&lt;br /&gt;Location     :  LU, Luxembourg&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  49°75'00" North&lt;br /&gt;Longitude    :   6°16'67" East&lt;br /&gt;&lt;br /&gt;OrgName:    Latin American and Caribbean IP address Regional Registry&lt;br /&gt;OrgID:      LACNIC&lt;br /&gt;Address:    Rambla Republica de Mexico 6125&lt;br /&gt;City:       Montevideo&lt;br /&gt;StateProv:&lt;br /&gt;PostalCode: 11400&lt;br /&gt;Country:    UY&lt;br /&gt;&lt;br /&gt;IP Address   : 22.189.227.141 [ 22.189.227.141 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : -&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  38°00'00" North&lt;br /&gt;Longitude    :  97°00'00" West&lt;br /&gt;OrgName:     : DoD Network Information Center&lt;br /&gt;OrgID:       : DNIC&lt;br /&gt;Address:     : 3990 E. Broad Street&lt;br /&gt;City:        : Columbus&lt;br /&gt;StateProv:   : OH&lt;br /&gt;PostalCode:  : 43218&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 158.176.170.220 [ 158.176.170.220 ]&lt;br /&gt;ISP          : KPMG Peat Marwick&lt;br /&gt;Organization : KPMG Peat Marwick&lt;br /&gt;Location     :  GB, United Kingdom&lt;br /&gt;City         : Wales, C9 -&lt;br /&gt;Latitude     :  53°33'33" North&lt;br /&gt;Longitude    :   1°28'33" West&lt;br /&gt;&lt;br /&gt;IP Address   : 192.230.95.221 [ 192.230.95.221 ]&lt;br /&gt;ISP          : No Record (Unknown)&lt;br /&gt;&lt;br /&gt;IP Address   : 90.44.151.20 [ AOrleans-158-1-20-20.w90-44.abo.wanadoo.fr ]&lt;br /&gt;ISP          : France Telecom&lt;br /&gt;Organization : France Telecom&lt;br /&gt;Location     :  FR, France&lt;br /&gt;City         : Paris, A8 -&lt;br /&gt;Latitude     :  48°86'67" North&lt;br /&gt;Longitude    :   2°33'33" East&lt;br /&gt;&lt;br /&gt;IP Address   : 169.100.95.158 [ 169.100.95.158 ]&lt;br /&gt;ISP          : J.P. Morgan &amp;amp; Co.&lt;br /&gt;Organization : JP Morgan Chase &amp;amp; Co&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : New York, NY 10271&lt;br /&gt;Latitude     :  40°70'87" North&lt;br /&gt;Longitude    :  74°01'04" West&lt;br /&gt;&lt;br /&gt;IP Address   : 192.186.30.157 [ 192.186.30.157 ]&lt;br /&gt;ISP          : No Record (Unknown)&lt;br /&gt;&lt;br /&gt;IP Address   : 200.245.134.68 [ 200.245.134.68 ]&lt;br /&gt;ISP          : EMBRATEL-EMPRESA BRASILEIRA DE TELECOMUNICAÇÕES SA&lt;br /&gt;Organization : LABORATORIO SARDALINA LTDA.&lt;br /&gt;Location     :  BR, Brazil&lt;br /&gt;City         : Diadema, 27 -&lt;br /&gt;Latitude     :  23°70'00" South&lt;br /&gt;Longitude    :  46°61'67" West&lt;br /&gt;&lt;br /&gt;----Port 22 -----------------&lt;br /&gt;IP Address   : 59.42.254.53 [ 59.42.254.53 ]&lt;br /&gt;ISP          : CHINANET Guangdong province network&lt;br /&gt;Organization : ChinaNet Guangdong Province Network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Guangzhou, 30 -&lt;br /&gt;Latitude     :  23°11'67" North&lt;br /&gt;Longitude    : 113°25'00" East&lt;br /&gt;&lt;br /&gt;----Port 1433 ---------------&lt;br /&gt;IP Address   : 69.238.4.7 [ 69-238-4-7.absolutetechnologies.com ]&lt;br /&gt;ISP          : SBC Internet Services&lt;br /&gt;Organization : Absolute Technologies&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Yorba Linda, CA 92887&lt;br /&gt;Latitude     :  33°88'79" North&lt;br /&gt;Longitude    : 117°72'86" West&lt;br /&gt;&lt;br /&gt;IP Address   : 61.191.224.19 [ 61.191.224.19 ]&lt;br /&gt;ISP          : Data Communication Division&lt;br /&gt;Organization : CHINANET Anhui province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Hefei, 01 -&lt;br /&gt;Latitude     :  31°86'39" North&lt;br /&gt;Longitude    : 117°28'08" East&lt;br /&gt;&lt;br /&gt;IP Address   : 69.179.108.90 [ 69-179-108-90.dyn.centurytel.net ]&lt;br /&gt;ISP          : CenturyTel Internet Holdings&lt;br /&gt;Organization : CenturyTel Internet Holdings&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  38°00'00" North&lt;br /&gt;Longitude    :  97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address   : 125.76.215.14 [ 125.76.215.14 ]&lt;br /&gt;ISP          : CHINANET Shanxi(SN) province network&lt;br /&gt;Organization : CHINANET Shanxi(SN) province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Beijing, 22 -&lt;br /&gt;Latitude     :  39°92'89" North&lt;br /&gt;Longitude    : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 1434 ---------------&lt;br /&gt;IP Address   : 161.53.169.2 [ merkur.fesb.hr ]&lt;br /&gt;ISP          : Croatian Academic and Research Network (CARNet)&lt;br /&gt;Organization : Croatian Academic and Research Network (CARNet)&lt;br /&gt;Location     :  HR, Croatia&lt;br /&gt;City         : Zagreb, 21 -&lt;br /&gt;Latitude     :  45°80'00" North&lt;br /&gt;Longitude    :  16°00'00" East&lt;br /&gt;&lt;br /&gt;----Port 2967 ----------------&lt;br /&gt;IP Address   : 69.122.209.109 [ ool-457ad16d.dyn.optonline.net ]&lt;br /&gt;ISP          : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Westbury, NY -&lt;br /&gt;Latitude     :  40°75'70" North&lt;br /&gt;Longitude    :  73°58'14" West&lt;br /&gt;&lt;br /&gt;----Port 5900 ----------------&lt;br /&gt;IP Address   : 124.224.131.247 [ 124.224.131.247 ]&lt;br /&gt;ISP          : CHINANET ningxia province network&lt;br /&gt;Organization : CHINANET ningxia province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Beijing, 22 -&lt;br /&gt;Latitude     :  39°92'89" North&lt;br /&gt;Longitude    : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address   : 190.160.48.168 [ 190.160.48.168 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : VTR Banda Ancha S.A.&lt;br /&gt;Location     :  CL, Chile&lt;br /&gt;City         : Santiago, 12 -&lt;br /&gt;Latitude     :  33°45'00" South&lt;br /&gt;Longitude    :  70°66'67" West&lt;br /&gt;&lt;br /&gt;IP Address   : 88.2.137.74 [ 74.Red-88-2-137.staticIP.rima-tde.net ]&lt;br /&gt;ISP          : Telefonica de Espana&lt;br /&gt;Organization : Telefonica de Espana&lt;br /&gt;Location     :  ES, Spain&lt;br /&gt;City         : Palma, 07 -&lt;br /&gt;Latitude     :  39°56'67" North&lt;br /&gt;Longitude    :   2°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 86.210.6.38 [ ANantes-256-1-87-38.w86-210.abo.wanadoo.fr ]&lt;br /&gt;ISP          : France Telecom&lt;br /&gt;Organization : France Telecom&lt;br /&gt;Location     :  FR, France&lt;br /&gt;City         : Nantes, B5 -&lt;br /&gt;Latitude     :  47°21'67" North&lt;br /&gt;Longitude    :   1°55'00" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-3131167467248470460?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/3131167467248470460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=3131167467248470460' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/3131167467248470460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/3131167467248470460'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/11/cyber-center-report-november-1-2007.html' title='Cyber Center Report - November 1, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-7573316647484138098</id><published>2007-10-31T15:40:00.000-04:00</published><updated>2007-10-31T15:41:41.834-04:00</updated><title type='text'>Cyber Center Report - October 31, 2007</title><content type='html'>BLSS Cyber Center Report - 31 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;www.blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The BLSS Cyber Center has detected new activity on port 53, one IP from Korea and IP from China.  China and Korea still continue probing/attacking on all previously reported ports within an increased tenacity.  Disabling port 7212 seems to prevent probes/attacks in successfully activating the Microsoft Service Pack Update (Software Updates) and Help Center Service system.  The BLSS Cyber Center, however, will continue to monitor such probes/attacks to detect a possible "work-around" from China, Korea, etc.&lt;br /&gt;&lt;br /&gt;Port 53; Korea (new site), China (new site). Port 1024; Russia (new site).&lt;br /&gt;Port 1026; China (3 new sites), U.S. the IANA probed 5 times last night, Apple Computers, Hewlett-Packard, XO Communications, Japan (2 new site), Australia (new site), Korea (new site), Canada (new site). Port 1027; Canada (new site). Port 1028; Canada (new site). Port 21; China (new site).  Port 22; U.S. (new site). Port 1433; Romania (new site), China (2 new sites), U.S. (new site). Port 1434; China (new site).  Port 3128; Korea (new site).&lt;br /&gt;Port 4899; Argentina (new site). Port 5900; China (new site), Korea (new site), Netherlands (new site), U.S. (2 new sites), Canada (2 new sites).&lt;br /&gt;Honey Pot Activity; U.S. (new site).  Port 80 surf only.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----Port 53 (new) ---------------&lt;br /&gt;IP Address   : 220.88.20.5 [ 220.88.20.5 ]&lt;br /&gt;ISP          : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  37°00'00" North&lt;br /&gt;Longitude    : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 221.136.24.36 [ 221.136.24.36 ]&lt;br /&gt;ISP          : NBIP CNC(Ningbo)info-Port co.,Ltd&lt;br /&gt;Organization : NBIP TongLian(Ningbo)info-Port co.,Ltd&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Ningbo, 02 -&lt;br /&gt;Latitude     :  29°87'50" North&lt;br /&gt;Longitude    : 121°54'19" East&lt;br /&gt;&lt;br /&gt;----Port 1024 -------------------&lt;br /&gt;IP Address   : 81.29.241.22 [ 81.29.241.22 ]&lt;br /&gt;ISP          : LLC GlobalWholesaleTrade&lt;br /&gt;Organization : LLC GlobalWholesaleTrade&lt;br /&gt;Location     :  RU, Russian Federation&lt;br /&gt;City         : Moscow, 48 -&lt;br /&gt;Latitude     :  55°75'22" North&lt;br /&gt;Longitude    :  37°61'56" East&lt;br /&gt;&lt;br /&gt;----Port 1026 -------------------&lt;br /&gt;IP Address   : 221.209.110.50 [ 221.209.110.50 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Mudanjiang, 08 -&lt;br /&gt;Latitude     :  44°58'33" North&lt;br /&gt;Longitude    : 129°60'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 221.208.208.100 [ 221.208.208.100 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Harbin, 08 -&lt;br /&gt;Latitude     :  45°75'00" North&lt;br /&gt;Longitude    : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 221.208.208.92 [ 221.208.208.92 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Harbin, 08 -&lt;br /&gt;Latitude     :  45°75'00" North&lt;br /&gt;Longitude    : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 106.26.68.11 [ 106.26.68.11 ]&lt;br /&gt;OrgName:     : Internet Assigned Numbers Authority&lt;br /&gt;OrgID:       : IANA&lt;br /&gt;Address:     : 4676 Admiralty Way, Suite 330&lt;br /&gt;City:        : Marina del Rey&lt;br /&gt;StateProv:   : CA&lt;br /&gt;PostalCode:  : 90292-6695&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 183.80.106.179 [ 183.80.106.179 ]&lt;br /&gt;OrgName:     : Internet Assigned Numbers Authority&lt;br /&gt;OrgID:       : IANA&lt;br /&gt;Address:     : 4676 Admiralty Way, Suite 330&lt;br /&gt;City:        : Marina del Rey&lt;br /&gt;StateProv:   : CA&lt;br /&gt;PostalCode:  : 90292-6695&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 126.122.46.85 [ softbank126122046085.bbtec.net ]&lt;br /&gt;ISP          : searched the APNIC whois database for an address t&lt;br /&gt;Organization : Softbank BB Corp&lt;br /&gt;Location     :  JP, Japan&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  36°00'00" North&lt;br /&gt;Longitude    : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 119.70.217.23 [ 119.70.217.23 ]&lt;br /&gt;OrgName:     : Asia Pacific Network Information Centre&lt;br /&gt;OrgID:       : APNIC&lt;br /&gt;Address:     : PO Box 2131&lt;br /&gt;City:        : Milton&lt;br /&gt;StateProv:   : QLD&lt;br /&gt;PostalCode:  : 4064&lt;br /&gt;Country:     : AU&lt;br /&gt;&lt;br /&gt;IP Address   : 60.45.233.13 [ p1013-ipbf10sinnagasak.nagasaki.ocn.ne.jp ]&lt;br /&gt;ISP          : NTT Communications Corporation&lt;br /&gt;Organization : Open Computer Network&lt;br /&gt;Location     :  JP, Japan&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  36°00'00" North&lt;br /&gt;Longitude    : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 184.180.230.100 [ 184.180.230.100 ]&lt;br /&gt;OrgName:     : Internet Assigned Numbers Authority&lt;br /&gt;OrgID:       : IANA&lt;br /&gt;Address:     : 4676 Admiralty Way, Suite 330&lt;br /&gt;City:        : Marina del Rey&lt;br /&gt;StateProv:   : CA&lt;br /&gt;PostalCode:  : 90292-6695&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 17.29.248.133 [ 17.29.248.133 ]&lt;br /&gt;ISP          : APPLE COMPUTER&lt;br /&gt;Organization : APPLE COMPUTER&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Cupertino, CA 95014&lt;br /&gt;Latitude     :  37°30'42" North&lt;br /&gt;Longitude    : 122°09'46" West&lt;br /&gt;&lt;br /&gt;IP Address   : 185.17.11.96 [ 185.17.11.96 ]&lt;br /&gt;OrgName:     : Internet Assigned Numbers Authority&lt;br /&gt;OrgID:       : IANA&lt;br /&gt;Address:     : 4676 Admiralty Way, Suite 330&lt;br /&gt;City:        : Marina del Rey&lt;br /&gt;StateProv:   : CA&lt;br /&gt;PostalCode:  : 90292-6695&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 16.10.71.38 [ 16.10.71.38 ]&lt;br /&gt;ISP          : HEWLETT-PACKARD COMPANY&lt;br /&gt;Organization : Hewlett-Packard Company&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Palo Alto, CA 94304&lt;br /&gt;Latitude     :  37°37'62" North&lt;br /&gt;Longitude    : 122°18'26" West&lt;br /&gt;&lt;br /&gt;IP Address   : 24.64.58.9 [ 24.64.58.9 ]&lt;br /&gt;ISP          : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  60°00'00" North&lt;br /&gt;Longitude    :  95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address   : 110.180.202.35 [ 110.180.202.35 ]&lt;br /&gt;OrgName:     : Internet Assigned Numbers Authority&lt;br /&gt;OrgID:       : IANA&lt;br /&gt;Address:     : 4676 Admiralty Way, Suite 330&lt;br /&gt;City:        : Marina del Rey&lt;br /&gt;StateProv:   : CA&lt;br /&gt;PostalCode:  : 90292-6695&lt;br /&gt;Country:     : US&lt;br /&gt;&lt;br /&gt;IP Address   : 124.198.13.163 [ 124.198.13.163 ]&lt;br /&gt;ISP          : HAIonNet&lt;br /&gt;Organization : campusmedia&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : Seoul, 11 -&lt;br /&gt;Latitude     :  37°56'64" North&lt;br /&gt;Longitude    : 126°99'97" East&lt;br /&gt;&lt;br /&gt;IP Address   : 67.91.4.156 [ ip67-91-4-156.z4-91-67.customer.algx.net ]&lt;br /&gt;ISP          : XO Communications&lt;br /&gt;Organization : XO Communications&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  38°00'00" North&lt;br /&gt;Longitude    :  97°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1027 -------------&lt;br /&gt;IP Address   : 24.64.58.9 [ 24.64.58.9 ]&lt;br /&gt;ISP          : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  60°00'00" North&lt;br /&gt;Longitude    :  95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1028 --------------&lt;br /&gt;IP Address   : 24.64.58.9 [ 24.64.58.9 ]&lt;br /&gt;ISP          : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  60°00'00" North&lt;br /&gt;Longitude    :  95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 21 ---------------&lt;br /&gt;IP Address   : 202.202.170.171 [ 202.202.170.171 ]&lt;br /&gt;ISP          : China Education and Research Network&lt;br /&gt;Organization : Chongqing Three Geoges College&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Chongqing, 33 -&lt;br /&gt;Latitude     :  29°56'28" North&lt;br /&gt;Longitude    : 106°55'28" East&lt;br /&gt;&lt;br /&gt;----Port 22 ----------------&lt;br /&gt;IP Address   : 66.121.60.18 [ adsl-66-121-60-18.dsl.lsan03.pacbell.net ]&lt;br /&gt;ISP          : SBC Internet Services&lt;br /&gt;Organization : SBC Internet Services&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Inglewood, CA -&lt;br /&gt;Latitude     :  33°95'20" North&lt;br /&gt;Longitude    : 118°34'77" West&lt;br /&gt;&lt;br /&gt;----Port 1433 ---------------&lt;br /&gt;IP Address   : 195.182.220.122 [ 195.182.220.122 ]&lt;br /&gt;ISP          : SC. CONDIV IMPEX SRL.&lt;br /&gt;Organization : SC. CONDIV IMPEX SRL.&lt;br /&gt;Location     :  RO, Romania&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  46°00'00" North&lt;br /&gt;Longitude    :  25°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 60.218.104.190 [ 60.218.104.190 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Harbin, 08 -&lt;br /&gt;Latitude     :  45°75'00" North&lt;br /&gt;Longitude    : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 71.162.124.178 [&lt;br /&gt;static-71-162-124-178.bstnma.fios.verizon.net ]&lt;br /&gt;ISP          : Verizon Internet Services&lt;br /&gt;Organization : DAVID DOHERTY&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Winchester, MA 01890&lt;br /&gt;Latitude     :  42°45'47" North&lt;br /&gt;Longitude    :  71°15'02" West&lt;br /&gt;&lt;br /&gt;----Port 1434 ---------------&lt;br /&gt;IP Address   : 58.242.184.222 [ 58.242.184.222 ]&lt;br /&gt;ISP          : CNC Group AnHui province network&lt;br /&gt;Organization : CNC Group AnHui province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Hefei, 01 -&lt;br /&gt;Latitude     :  31°86'39" North&lt;br /&gt;Longitude    : 117°28'08" East&lt;br /&gt;&lt;br /&gt;----Port 3128 ---------------&lt;br /&gt;IP Address   : 61.85.202.38 [ 61.85.202.38 ]&lt;br /&gt;ISP          : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  37°00'00" North&lt;br /&gt;Longitude    : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Port 4899 ----------------&lt;br /&gt;IP Address   : 201.234.99.242 [ 201.234.99.242 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : IMPSAT FIBER NETWORKS INC&lt;br /&gt;Location     :  AR, Argentina&lt;br /&gt;City         : Buenos Aires, 07 -&lt;br /&gt;Latitude     :  34°58'75" South&lt;br /&gt;Longitude    :  58°67'25" West&lt;br /&gt;&lt;br /&gt;----Port 5900 --------------------&lt;br /&gt;IP Address   : 202.96.155.134 [ 202.96.155.134 ]&lt;br /&gt;ISP          : CHINANET Guangdong province network&lt;br /&gt;Organization : ChinaNet Guangdong Province Network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Guangzhou, 30 -&lt;br /&gt;Latitude     :  23°11'67" North&lt;br /&gt;Longitude    : 113°25'00" East&lt;br /&gt;&lt;br /&gt;IP Address   : 69.80.166.124 [ 69.80.166.124 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : SUNY Brockport&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Brockport, NY 14420&lt;br /&gt;Latitude     :  43°25'08" North&lt;br /&gt;Longitude    :  77°92'46" West&lt;br /&gt;&lt;br /&gt;IP Address   : 69.176.178.178 [ 69.176.178.178 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : City West Cable &amp;amp; Telephone Corp.&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : Prince Rupert, BC v8j1l1&lt;br /&gt;Latitude     :  54°31'67" North&lt;br /&gt;Longitude    : 130°33'34" West&lt;br /&gt;&lt;br /&gt;IP Address   : 84.84.136.217 [ ip545488d9.speed.planet.nl ]&lt;br /&gt;ISP          : World Access / Planet Internet&lt;br /&gt;Organization : Planet Technologies&lt;br /&gt;Location     :  NL, Netherlands&lt;br /&gt;City         : Hattem, 03 -&lt;br /&gt;Latitude     :  52°46'67" North&lt;br /&gt;Longitude    :   6°06'67" East&lt;br /&gt;&lt;br /&gt;IP Address   : 76.181.103.166 [ cpe-76-181-103-166.columbus.res.rr.com ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : Road Runner&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Greensboro, NC -&lt;br /&gt;Latitude     :  36°08'44" North&lt;br /&gt;Longitude    :  79°82'09" West&lt;br /&gt;&lt;br /&gt;IP Address   : 69.158.64.21 [ bas14-toronto12-1167998997.dsl.bell.ca ]&lt;br /&gt;ISP          : Bell Canada&lt;br /&gt;Organization : Sympatico&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : Rexdale, ON -&lt;br /&gt;Latitude     :  43°71'67" North&lt;br /&gt;Longitude    :  79°56'67" West&lt;br /&gt;&lt;br /&gt;IP Address   : 221.148.61.236 [ 221.148.61.236 ]&lt;br /&gt;ISP          : Korea Telecom&lt;br /&gt;Organization : (sa)hangugsaneobgyungjeyeunguwon&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  37°00'00" North&lt;br /&gt;Longitude    : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity --------&lt;br /&gt;Activity     : Port 80 surf only&lt;br /&gt;IP Address   : 168.91.1.189 [ 168.91.1.189 ]&lt;br /&gt;ISP          : IVYTech&lt;br /&gt;Organization : IVYTech Community College of Indiana&lt;br /&gt;Location     :  US, United States&lt;br /&gt;City         : Indianapolis, IN 46208&lt;br /&gt;Latitude     :  39°83'31" North&lt;br /&gt;Longitude    :  86°17'47" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-7573316647484138098?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/7573316647484138098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=7573316647484138098' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7573316647484138098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7573316647484138098'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-31-2007.html' title='Cyber Center Report - October 31, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-6527203051698314906</id><published>2007-10-29T14:26:00.000-04:00</published><updated>2007-10-29T14:29:12.840-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Korea'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='blacoked IP'/><category scheme='http://www.blogger.com/atom/ns#' term='Attacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Thailand'/><category scheme='http://www.blogger.com/atom/ns#' term='Taiwan'/><category scheme='http://www.blogger.com/atom/ns#' term='firewall IP'/><title type='text'>Recommended IPs Addresses to be Blocked - China, Korea, Taiwan, and Thailand</title><content type='html'>The BLSS Cyber Center is recommending that the following (additional) IP addresses from China, Korea, Taiwan and Thailand be entered into Firewalls:&lt;br /&gt;&lt;br /&gt;IP Address       Country&lt;br /&gt;----------       -------&lt;br /&gt;125.76.238.164   China - Shanxi&lt;br /&gt;219.148.119.2    China - Hebei&lt;br /&gt;116.18.161.55    China - Guangdong&lt;br /&gt;222.216.28.161   China - Guangxi&lt;br /&gt;222.217.240.248  China - Guangxi&lt;br /&gt;121.18.13.107    China - Hebei&lt;br /&gt;218.10.137.130   China - Heilongjiang&lt;br /&gt;221.208.208.101  China - Heilongjiang&lt;br /&gt;221.208.208.3    China - Heilongjiang&lt;br /&gt;221.208.208.83   China - Heilongjiang&lt;br /&gt;221.208.208.91   China - Heilongjiang&lt;br /&gt;221.208.208.95   China - Heilongjiang&lt;br /&gt;221.208.208.98   China - Heilongjiang&lt;br /&gt;221.209.110.50   China - Mudanjiang&lt;br /&gt;218.3.134.250    China - China Shipbuilding Inst&lt;br /&gt;59.72.128.14     China - Beihua Univ&lt;br /&gt;58.247.50.243    China - ShangHai&lt;br /&gt;222.215.136.52   China - Sichuan&lt;br /&gt;218.50.1.119     Korea - Hanaro Telecomm&lt;br /&gt;218.232.95.60    Korea - Hanaro Telecomm&lt;br /&gt;211.67.58.203    China - Wuhan - Inst Science/Tech&lt;br /&gt;61.134.56.18     China - Shanghai&lt;br /&gt;58.20.228.52     China - Changsa&lt;br /&gt;122.116.17.133   Taiwan - Taipei&lt;br /&gt;121.18.12.197    China - Hebei&lt;br /&gt;218.10.137.42    China - Harbin&lt;br /&gt;61.184.101.46    China - Wuhan&lt;br /&gt;218.10.137.42    China - Harbin&lt;br /&gt;218.10.137.42    China - Harbin&lt;br /&gt;202.97.238.202   China - Heilongjiang&lt;br /&gt;219.240.44.147   Korea - Seocho&lt;br /&gt;221.139.35.78    Korea - Islan&lt;br /&gt;218.10.137.142   China - Harbin&lt;br /&gt;221.209.110.20   China - Mudanjiang&lt;br /&gt;124.114.116.18   China - Beijing&lt;br /&gt;219.147.233.40   China - Zhongshan&lt;br /&gt;218.75.199.50    China - Hunan&lt;br /&gt;218.165.8.32     Taiwan - Taipei&lt;br /&gt;222.169.226.169  China - Changchun&lt;br /&gt;222.239.255.43   Korea - Soul&lt;br /&gt;61.130.50.150    China - Quzhou&lt;br /&gt;221.158.228.40   Korea - Korea Telecomm&lt;br /&gt;221.141.127.137  Korea -Ilsan&lt;br /&gt;221.209.110.50   China - Mudanjiang&lt;br /&gt;218.10.137.142   China - Harbin&lt;br /&gt;221.209.110.20   China - Mudanjiang&lt;br /&gt;202.75.218.145   China - Hangzhou&lt;br /&gt;61.189.154.33    China - Shanghai&lt;br /&gt;218.106.91.25    China - Hefei&lt;br /&gt;220.191.233.132  China - Taizhou&lt;br /&gt;220.179.244.138  China - Hefei&lt;br /&gt;61.175.243.182   China - Jinyun&lt;br /&gt;58.241.178.213   China - Xuzhou&lt;br /&gt;58.97.5.64       Thailand - Bangkok&lt;br /&gt;222.217.221.224  China - Nanning&lt;br /&gt;122.38.90.165    Korea&lt;br /&gt;218.234.38.39    Korea - Seocho&lt;br /&gt;221.11.6.197     China - Taiyuan&lt;br /&gt;59.56.27.170     China - Beijing&lt;br /&gt;219.153.5.169    China - Shanghai&lt;br /&gt;220.191.252.62   China - Lishui&lt;br /&gt;58.241.178.210   China - Xuzhou&lt;br /&gt;61.130.134.66    China - Hangzhou&lt;br /&gt;222.216.28.178   China - Nanning&lt;br /&gt;124.224.131.132  China - Beijing&lt;br /&gt;218.234.41.8     Korea - Seocho&lt;br /&gt;218.27.148.78    China - Changchun&lt;br /&gt;218.3.134.250    China - Zhenjiang&lt;br /&gt;218.234.32.131   Korea - Seocho&lt;br /&gt;218.153.221.29   Korea&lt;br /&gt;122.136.45.2     China - Changchun&lt;br /&gt;219.147.233.30   China - Zhongshan&lt;br /&gt;58.38.3.178      China - Shanghai&lt;br /&gt;58.247.11.242    China - Shanghai&lt;br /&gt;124.226.234.15   China - Nanning&lt;br /&gt;123.8.228.123    China - Beijing&lt;br /&gt;211.174.179.32   Korea - Seoul&lt;br /&gt;124.224.128.140  China - Beijing&lt;br /&gt;218.234.38.69    Korea - Seocho&lt;br /&gt;218.26.89.141    China - Changzhi&lt;br /&gt;121.139.129.4    Korea - Keieii&lt;br /&gt;222.217.221.214  China - Nanning&lt;br /&gt;221.6.7.89       China - Nanning&lt;br /&gt;220.165.8.32     China - Beijing&lt;br /&gt;219.153.47.134   China - Shanghai&lt;br /&gt;124.132.3.222    China - Jinan&lt;br /&gt;221.194.46.204   China - Hebei&lt;br /&gt;203.151.151.246  China - Thailand&lt;br /&gt;210.202.199.132  Taiwan - Taichung&lt;br /&gt;218.92.205.106   China - Beijing&lt;br /&gt;125.225.22.110   Taiwan - Taipei&lt;br /&gt;210.51.187.88    China - Bejing&lt;br /&gt;218.38.56.170    Korea&lt;br /&gt;218.108.70.246   China - Chaoyang&lt;br /&gt;60.175.101.20    China - Hefei&lt;br /&gt;58.246.107.14    China - Shanghai&lt;br /&gt;219.153.5.169    China - Shanghai&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-6527203051698314906?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/6527203051698314906/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=6527203051698314906' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6527203051698314906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6527203051698314906'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/recommended-ips-addresses-to-be-blocked.html' title='Recommended IPs Addresses to be Blocked - China, Korea, Taiwan, and Thailand'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-6749477250780259376</id><published>2007-10-29T14:23:00.000-04:00</published><updated>2007-10-29T14:26:16.472-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='atack'/><category scheme='http://www.blogger.com/atom/ns#' term='BITS'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><category scheme='http://www.blogger.com/atom/ns#' term='Patch'/><category scheme='http://www.blogger.com/atom/ns#' term='background intelligent transfer service'/><title type='text'>Additional Attack Context</title><content type='html'>Additional context to the latest set of BLSS Cyber Reports.  As we are researching the techniques deployed, we found one approach documented in May 2007 that used the Microsoft Patch or Update Service (aka BITS – background intelligent transfer service).  This knowledge seems to be well dispersed in the underground hacking community and could be the technique or some variation of the techniques that we have witness in the past few days.&lt;br /&gt;&lt;br /&gt;Please see :&lt;br /&gt;&lt;br /&gt;New Attack Piggybacks on Microsoft's Patch Service (Washington Post – May 2007)&lt;br /&gt; &lt;a href="http://blog.washingtonpost.com/securityfix/2007/05/malware_using_microsoft_patch.html"&gt;http://blog.washingtonpost.com/securityfix/2007/05/malware_using_microsoft_patch.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-6749477250780259376?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/6749477250780259376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=6749477250780259376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6749477250780259376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6749477250780259376'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/additional-attack-context.html' title='Additional Attack Context'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-2281186180134201178</id><published>2007-10-29T14:17:00.000-04:00</published><updated>2007-10-29T14:22:55.294-04:00</updated><title type='text'>Cyber Center Report - October 29, 2007</title><content type='html'>BLSS Cyber Center Report - 29 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;www.blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This BLSS Cyber Center Report is a continuation of the Cyber Center Report published on 29 October 2007.  BLSS has initiated an immediate analysis on the China attack of our Honey Pot, which was reported yesterday, 28 October 2007.  This report will be categorized into two separate sections; 1) Analysis Of Honey Pot Attack, and 2) Advised Immediate Action Required To Prevent The Attacks.&lt;br /&gt;&lt;br /&gt;Analysis Of Honey Pot Attack&lt;br /&gt;----------------------------&lt;br /&gt;&lt;br /&gt;Below are the first 100 program file payloads detected by Shadow.  There were many more payloads installed into the "i386" and "Service Pack" nested folders.  The most interesting fact about the first 100 payloads below, is that almost all the payloads are related to "Remote Access" functions. The fact is that the RegCode.dll, Adfsocm.dll, ComAdmin.dll, Dialer.exe, the "System Configuration Install" (system.configuration.install.dll), Nfsocm.dll, Explorer.exe, etc. But most interesting, is the fact that remote access program payloads were updated, along with the \Windows\PCHealth\HelpCtr\System\RemoteAssistance\Interaction\Client\Raclient.js, Racontrol.js, Raserver.js and Common.js, along with a new RegEdit.exe. &lt;br /&gt;&lt;br /&gt;The following are the first 100 payloads detected:&lt;br /&gt;&lt;br /&gt;1. C:\WINDOWS\ASSEMBLY\GAC\REGCODE\1.0.5000.0__B03F5F7F11D50A3A\REGCODE.DLL&lt;br /&gt;2. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\NEWBINS\I386\ADFSOCM.DLL&lt;br /&gt;3. C:\WINDOWS\SYSTEM32\COM\COMADMIN.DLL&lt;br /&gt;4. C:\WINDOWS\DIALER.EXE&lt;br /&gt;5. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.CONFIGURATION.INSTALL\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.CONFIGURATION.INSTALL.DLL&lt;br /&gt;6. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\NEWBINS\I386\NFSOCM.DLL&lt;br /&gt;7. C:\WINDOWS\EXPLORER.EXE&lt;br /&gt;8. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.DATA\1.0.5000.0__B77A5C561934E089\SYSTEM.DATA.DLL&lt;br /&gt;9. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\NEWBINS\I386\OCWSS.DLL&lt;br /&gt;10. C:\PROGRAM FILES\COMMONFILES\SPEECHENGINES\MICROSOFT\TTS\1033\SPTTSENG.DLL&lt;br /&gt;11. C:\WINDOWS\HH.EXE&lt;br /&gt;12. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.DATA.ORACLECLIENT\1.0.5000.0__B77A5C561934E089\SYSTEM.DATA.ORACLECLIENT.DLL&lt;br /&gt;13. C:\WINDOWS\PCHEALTH\HELPCTR\SYSTEM\REMOTEASSISTANCE\INTERACTION\CLIENT\RACLIENT.JS&lt;br /&gt;14. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\NEWBINS\I386\SUAIDMOG.DLL&lt;br /&gt;15. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MUI\0409\MSCORSECR.DLL&lt;br /&gt;16. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.DIRECTORYSERVICES\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.DIRECTORYSERVICES.DLL&lt;br /&gt;17. C:\WINDOWS\NOTEPAD.EXE&lt;br /&gt;18. C:\WINDOWS\PCHEALTH\HELPCTR\SYSTEM\REMOTEASSISTANCE\INTERACTION\COMMON\RACONTROL.JS&lt;br /&gt;19. C:\WINDOWS\PCHEALTH\HELPCTR\SYSTEM\REMOTE ASSISTANCE\COMMON\COMMON.JS&lt;br /&gt;20. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.ENTERPRISESERVICES\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.ENTERPRISESERVICES.DLL&lt;br /&gt;21. C:\WINDOWS\REGEDIT.EXE&lt;br /&gt;22. C:\WINDOWS\PCHEALTH\HELPCTR\SYSTEM\REMOTEASSISTANCE\INTERACTION\SERVER\RASERVER.JS&lt;br /&gt;23. C:\WINDOWS\PCHEALTH\HELPCTR\SYSTEM\REMOTE ASSISTANCE\COMMON\CONSTANTS.JS&lt;br /&gt;24. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.ENTERPRISESERVICES\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.ENTERPRISESERVICES.THUNK.DLL&lt;br /&gt;25. C:\WINDOWS\SYSTEM32\MUI\0C0A\W03A2409.DLL&lt;br /&gt;26. C:\WINDOWS\TWAIN.DLL&lt;br /&gt;27. C:\WINDOWS\PCHEALTH\HELPCTR\VENDORS\CN=MICROSOFTCORPORATION,L=REDMOND,S=WASHINGTON,C=US\REMOTE ASSISTANCE\COMMON\COMMON.JS&lt;br /&gt;28. C:\WINDOWS\SYSTEM32\MUI\0C0A\WS03RES.DLL&lt;br /&gt;29. C:\WINDOWS\TWAIN_32.DLL&lt;br /&gt;30. C:\WINDOWS\PCHEALTH\HELPCTR\VENDORS\CN=MICROSOFTCORPORATION,L=REDMOND,S=WASHINGTON,C=US\REMOTEASSISTANCE\COMMON\CONSTANTS.JS&lt;br /&gt;31. C:\WINDOWS\SYSTEM32\MUI\0C0A\XPOB2RES.DLL&lt;br /&gt;32. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.MESSAGING\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.MESSAGING.DLL&lt;br /&gt;33. C:\WINDOWS\SYSTEM32\REINSTALLBACKUPS\0001\DRIVERFILES\I386\PROCESSR.SYS&lt;br /&gt;34. C:\WINDOWS\TWUNK_16.EXE&lt;br /&gt;35. C:\WINDOWS\SYSTEM32\MUI\0C0A\XPSP2RES.DLL&lt;br /&gt;36. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.RUNTIME.REMOTING\1.0.5000.0__B77A5C561934E089\SYSTEM.RUNTIME.REMOTING.DLL&lt;br /&gt;37. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\VDS11\DISKRAID.EXE&lt;br /&gt;38. C:\WINDOWS\TWUNK_32.EXE&lt;br /&gt;39. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.RUNTIME.SERIALIZATION.FORMATTERS.SOAP\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.RUNTIME.SERIALIZATION.FORMATTERS.SOAP.DLL&lt;br /&gt;40. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\VDS11\VDS.EXE&lt;br /&gt;41. C:\WINDOWS\UDDISP.EXE&lt;br /&gt;42. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.SECURITY\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.SECURITY.DLL&lt;br /&gt;43. C:\WINDOWS\INF\UNREGMP2.EXE&lt;br /&gt;44. C:\WINDOWS\SYSTEM32\WBEM\ADSTATUS\TRUSTMON.DLL&lt;br /&gt;45. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\VDS11\VDSDYNDR.DLL&lt;br /&gt;46. C:\WINDOWS\VMMREG32.DLL&lt;br /&gt;47. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.SERVICEPROCESS\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.SERVICEPROCESS.DLL&lt;br /&gt;48. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\VDS11\VDSLDR.EXE&lt;br /&gt;49. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WEB\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.WEB.DLL&lt;br /&gt;50. C:\WINDOWS\WINHELP.EXE&lt;br /&gt;51. C:\WINDOWS\SERVICEPACKFILES\SERVICEPACKCACHE\CMPNENTS\R2\PACKAGES\VDS11\VDSUTIL.DLL&lt;br /&gt;52. C:\WINDOWS\SYSTEM32\WBEM\XML\WMI2XML.DLL&lt;br /&gt;53. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WEB.MOBILE\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.WEB.MOBILE.DLL&lt;br /&gt;54. C:\WINDOWS\WINHLP32.EXE&lt;br /&gt;55. C:\WINDOWS\MSAGENT\AGENTANM.DLL&lt;br /&gt;56. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WEB.REGULAREXPRESSIONS\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.WEB.REGULAREXPRESSIONS.DLL&lt;br /&gt;57. C:\WINDOWS\MSAGENT\AGENTCTL.DLL&lt;br /&gt;58. C:\WINDOWS\_DEFAULT.PIF&lt;br /&gt;59. C:\WINDOWS\MSAGENT\AGENTDP2.DLL&lt;br /&gt;60. C:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WEB.SERVICES\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.WEB.SERVICES.DLL&lt;br /&gt;61. C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\WEB\ADMIN\HELP\0409\LINKCSS.JS&lt;br /&gt;62. C:\WINDOWS\MSAGENT\AGENTDPV.DLL&lt;br /&gt;63. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\MSCORLIB\1.0.5000.0__B77A5C561934E089_1C85CDAB\MSCORLIB.DLL&lt;br /&gt;64. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DAO\DAO360.DLL&lt;br /&gt;65. C:\WINDOWS\MSAGENT\AGENTMPX.DLL&lt;br /&gt;66. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM\1.0.5000.0__B77A5C561934E089_8DF1E0E7\SYSTEM.DLL&lt;br /&gt;67. C:\WINDOWS\MSAGENT\AGENTPSH.DLL&lt;br /&gt;68. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\IEINFO5.OCX&lt;br /&gt;69. C:\WINDOWS\MSAGENT\AGENTSR.DLL&lt;br /&gt;70. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\MSINFO32.EXE&lt;br /&gt;71. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.DESIGN\1.0.5000.0__B03F5F7F11D50A3A_2DC1A7DB\SYSTEM.DESIGN.DLL&lt;br /&gt;72. C:\WINDOWS\MSAGENT\AGENTSVR.EXE&lt;br /&gt;73. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SPEECH\SAPI.DLL&lt;br /&gt;74. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.DRAWING\1.0.5000.0__B03F5F7F11D50A3A_66784F17\SYSTEM.DRAWING.DLL&lt;br /&gt;75. C:\WINDOWS\MSAGENT\AGTINTL.DLL&lt;br /&gt;76. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SPEECH\SAPISVR.EXE&lt;br /&gt;77. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.DRAWING.DESIGN\1.0.5000.0__B03F5F7F11D50A3A_271DA28B\SYSTEM.DRAWING.DESIGN.DLL&lt;br /&gt;78. C:\WINDOWS\MSAGENT\MSLWVTTS.DLL&lt;br /&gt;79. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\TEXTCONV\MSCONV97.DLL&lt;br /&gt;80. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.WINDOWS.FORMS\1.0.5000.0__B77A5C561934E089_9D99100D\SYSTEM.WINDOWS.FORMS.DLL&lt;br /&gt;81. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\TRIEDIT\DHTMLED.OCX&lt;br /&gt;82. C:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.XML\1.0.5000.0__B77A5C561934E089_667035EA\SYSTEM.XML.DLL&lt;br /&gt;83. C:\WINDOWS\SRCHASST\MSGR3EN.DLL&lt;br /&gt;84. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\TRIEDIT\TRIEDIT.DLL&lt;br /&gt;85. C:\WINDOWS\SRCHASST\SRCHCTLS.DLL&lt;br /&gt;86. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\1033\ALINKUI.DLL&lt;br /&gt;87. C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VGX\VGX.DLL&lt;br /&gt;88. C:\WINDOWS\SRCHASST\SRCHUI.DLL&lt;br /&gt;89. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\1033\CSCOMPUI.DLL&lt;br /&gt;90. C:\PROGRAM FILES\COMMON FILES\SPEECHENGINES\MICROSOFT\SPCOMMON.DLL&lt;br /&gt;91. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\1033\VBC7UI.DLL&lt;br /&gt;92. C:\WINDOWS\SYSTEM32\6TO4SVC.DLL&lt;br /&gt;93. C:\PROGRAM FILES\COMMON FILES\SYSTEM\ADO\MSADER15.DLL&lt;br /&gt;94. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\1033\VSAVB7RTUI.DLL&lt;br /&gt;95. C:\WINDOWS\SYSTEM32\AAAAMON.DLL&lt;br /&gt;96. C:\PROGRAM FILES\COMMON FILES\SYSTEM\ADO\MSADO15.DLL&lt;br /&gt;97. C:\WINDOWS\SYSTEM32\ACCTRES.DLL&lt;br /&gt;98. C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASP.NETCLIENTFILES\SMARTNAV.JS&lt;br /&gt;99. C:\PROGRAM FILES\COMMON FILES\SYSTEM\ADO\MSADOMD.DLL&lt;br /&gt;100.C:\WINDOWS\SYSTEM32\ACCWIZ.EXE&lt;br /&gt;&lt;br /&gt;Advised Immediate Action Required To Prevent The Attacks&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;&lt;br /&gt;The first step, is to enter the following ports into firewalls, if organizations can do so without inhibiting the normal operations of your network and software:&lt;br /&gt;&lt;br /&gt;Port 7212&lt;br /&gt;Port 1026&lt;br /&gt;Port 1027&lt;br /&gt;Port 1028&lt;br /&gt;&lt;br /&gt;The second step, is to enter the following IP addresses into firewalls:&lt;br /&gt;&lt;br /&gt;IP Address&lt;br /&gt;----------&lt;br /&gt;121.18.13.107&lt;br /&gt;121.18.12.197&lt;br /&gt;221.208.208.83&lt;br /&gt;221.208.208.91&lt;br /&gt;221.208.208.95&lt;br /&gt;221.208.208.98&lt;br /&gt;202.97.238.202&lt;br /&gt;218.50.1.119&lt;br /&gt;222.239.255.43&lt;br /&gt;121.235.156.114&lt;br /&gt;210.79.152.144&lt;br /&gt;202.97.238.202&lt;br /&gt;221.208.208.101&lt;br /&gt;44.139.107.99&lt;br /&gt;&lt;br /&gt;The third step, is to TURN OFF all Automatic Updates and Disable the Microsoft Help Center Remote Access Functions.  As a "hardening method"&lt;br /&gt;within BLSS, we actually erase the following java scripts:&lt;br /&gt;&lt;br /&gt;Java Scripts&lt;br /&gt;-----------&lt;br /&gt;Raclient.js&lt;br /&gt;Racontrol.js&lt;br /&gt;Common.js&lt;br /&gt;Raserver.js&lt;br /&gt;Constants.js&lt;br /&gt;&lt;br /&gt;The BLSS Cyber Center will be publishing a list of all IP addresses detected from China and Korea within the next 24 hours.  It is recommended that all IP addresses from China and Korea be entered into firewalls as a security&lt;br /&gt;(safety) precaution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-2281186180134201178?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/2281186180134201178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=2281186180134201178' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/2281186180134201178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/2281186180134201178'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-29-2007.html' title='Cyber Center Report - October 29, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-4941635237150167870</id><published>2007-10-29T10:00:00.000-04:00</published><updated>2007-10-29T10:48:49.562-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Dorf'/><category scheme='http://www.blogger.com/atom/ns#' term='compromised systems'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Ecard'/><title type='text'>Storm Worm Research</title><content type='html'>Commenting on eWeek articles:&lt;br /&gt;NAC Can't Weather the Storm  - October 26, 2007&lt;br /&gt;&lt;a href="http://www.eweek.com/article2/0,1895,2207921,00.asp"&gt;http://www.eweek.com/article2/0,1895,2207921,00.asp&lt;/a&gt;&lt;br /&gt;Storm Worm Botnet Lobotomizing Anti-Virus Programs - October 24, 2007&lt;br /&gt;&lt;a href="http://www.eweek.com/article2/0,1895,2205606,00.asp"&gt;http://www.eweek.com/article2/0,1895,2205606,00.asp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Our Storm Worm Research&lt;br /&gt;&lt;br /&gt;The Storm worm and other nameless worms roaming the Internet today are extremely capable and are not beating with brute force techniques; they don’t need to base on the techniques being deployed. These worms are intruding networks and systems almost at will without logins, passwords, or help from insiders. There are hundreds of new compromised IPs added to the attack every day using the same attack profile and techniques.  Therefore blocking IPs and countries in your firewalls and other network access controls (NACs) from accessing your networks is a mission impossible. The actual attack is hidden is the overload of communications and probes that come from these compromised computers that intrude looking like normal expected communications.  Anti-virus and anti-spyware solutions are being rendered worst than useless since they are reporting that all is OK. &lt;br /&gt;&lt;br /&gt;Adjusting filters and behaviors in IPS systems and UTM systems is also nearly unproductive since these worms change their signature every 30 minutes or less. Once in, these worms are invisible because they comes with a rootkit built in and hide at the kernel level; and they are clever enough to change every few weeks (or days). These worms have built-in defense mechanisms and they know when they are being investigated, and it punishes and fights back.&lt;br /&gt;&lt;br /&gt;We are finding that the best security defense in depth (DiD) architectures with many security appliances and software products are having equally difficult problems in stopping theses worms. The filter sensitivities are different in each tool and analyzing a single event has many gaps in what the logs are showing. Since there are some many short-burst probes and attacks each day, the logs are extremely lengthy. Often after identifying an suspicious event, they files are gone since they are already were installed, make critical O/S changes or download other malware via open ports looking like valid communications, and then deleted themselves.&lt;br /&gt;&lt;br /&gt;So why is the information so vague about the storm worm?  It’s because the storm worm knows the weaknesses of security products available today and it doing a grand job of defeating and confusing computer security analysts.  A new security technology and approach is required by the industry.  As you see form the posted cyber reports, we are able to prevent, capture forensics, and analyze these worms without much difficulty. No need for filter adjustments or new signature updates for us. We see these attacks like watching a video game in near real-time.  By the way, we have not published our forensics and logs, but have provided this information through several channels.  We will remain discrete about how these attacks are so successful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-4941635237150167870?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/4941635237150167870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=4941635237150167870' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/4941635237150167870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/4941635237150167870'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/storm-worm-research.html' title='Storm Worm Research'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-464372168726400506</id><published>2007-10-29T07:55:00.000-04:00</published><updated>2007-10-29T15:33:14.676-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 28, 2007</title><content type='html'>BLSS Cyber Center Report - 28 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;BLSS detected and observed the highest number of new computers suddenly broadcasting over the Internet to date. China and Korea continue to escalate their probes/attacks on all previously reported ports. The number of IPs in China and Korea probing/attacking the U.S. is rising substantially each night.&lt;br /&gt;&lt;br /&gt;Please read this report carefully. Several government computers are now broadcasting over port 1026 UDP.&lt;br /&gt;&lt;br /&gt;BLSS also detected and captured the forensics of multiple IP connections from China (Hebei, Beijing and 3 Harbin IP sites), Japan, and one site inside the U.S. from an Amateur Radio Digital Communications Group.&lt;br /&gt;&lt;br /&gt;Several unauthorized files were detected from offshore sources (IPs) within the BLSS Honey Pot that included REGCODE.DLL and ADFSOCM.DLL.&lt;br /&gt;&lt;br /&gt;The following IPs were connected to the BLSS Honey Pot when these files were received:&lt;br /&gt;&lt;br /&gt;IP Address Location Port Protocol&lt;br /&gt;------------- ----------- ----- --------&lt;br /&gt;121.18.13.107 China - Hebei 7212 TCP&lt;br /&gt;121.235.156.114 China - Beijing 1026 UDP&lt;br /&gt;210.79.152.144 Japan 1026 UDP&lt;br /&gt;221.208.208.91 China - Harbin 1027 UDP&lt;br /&gt;202.97.238.202 China - Harbin 1027 UDP&lt;br /&gt;221.208.208.101 China - Harbin 1026 UDP&lt;br /&gt;44.139.107.99 U.S. 1026 UDP&lt;br /&gt;&lt;br /&gt;(IP 44.139.107.99 is located somewhere (approx) in Colorado at an Armature Radio Digital Communications Station)&lt;br /&gt;&lt;br /&gt;Several other key U.S. government computers are now suddenly broadcasting over port 1026 UDP;&lt;br /&gt;&lt;br /&gt;Four computers from the Naval Ocean Systems Center:&lt;br /&gt;&lt;br /&gt;1) 214.174.173.142&lt;br /&gt;2) 33.14.45.142&lt;br /&gt;3) 214.71.189.59&lt;br /&gt;4) 214.84.88.214&lt;br /&gt;&lt;br /&gt;One computer from the DoD Network Centric Operations:&lt;br /&gt;&lt;br /&gt;1) 26.198.93.126&lt;br /&gt;&lt;br /&gt;Several other computers now broadcasting on port 1026. from the U.S. there are; The IANA probed port 1026 a total number of eight times last night, from eight separate IP addresses, one computer from Hewlett-Packard Company, one computer from Cingular Wireless II, one computer from Road Runner, one computer from TDS Telecom, one computer the Buckeye Pipe Line Company.&lt;br /&gt;&lt;br /&gt;Other countries probing on Port 1026; China (new site), Korea (2 new sites), Japan (2 new sites), Canada (4 new sites – one of these computers is from Nortel Networks Canada), Italy (new site), Germany (new site), New Zealand (new site), United Kingdom, (new site), “Societe Internationale de Telecomm (Europe), One IP Address which has no record and cannot be traced (most likely belongs to a government agency), Australia (new site). Port 1027; Canada (new site), Israel (new site). Port 1028; Canada (new site). Port 21; China (new site). Port 22; Netherlands (new site), China (2 new sites), Japan (new site), U.S. (new site). Port 25; Taiwan (new site). Port 1080; China (new site), Korea (new site). Port 1433; Taiwan (new site), U.S. (new site), China (new site). Port 1434; China (2 new sites, including China Mobile Comm Corp). Port 2967; Spain (new site), U.S. (new site), China (new site). Port 2968; U.S. (new site). Port 3128; Germany (new site). Port 4899; China (new site), India (new site). Port 5900; Algeria (new site), China (2 new sites), Korea (new site). Port 7212; China (new site). Honey Port Activity; China surfed port 80 and attacked through port 1080, three hours after the service pack update was attempted. The Chinese attack failed. Germany surfed port 80 and attempted no attack. Ethiopia surfed port 80 and attempted no attack.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----Service Pack Update Activated During The Following IP Connections -----&lt;br /&gt;IP Address : 121.18.13.107 [ 121.18.13.107 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : CNC Group Hebei province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hebei, 10 -&lt;br /&gt;Latitude : 39°88'97" North&lt;br /&gt;Longitude : 115°27'50" East&lt;br /&gt;&lt;br /&gt;IP Address : 121.235.156.114 [&lt;br /&gt;114.156.235.121.broad.wx.js.dynamic.163data.com.cn ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 210.79.152.144 [ 144M61.rivo.mediatti.net ]&lt;br /&gt;ISP : Mediatti Communications Inc.&lt;br /&gt;Organization : Mediatti Communications,Inc.&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.208.208.91 [ 221.208.208.91 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 202.97.238.202 [ 202.97.238.202 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.208.208.101 [ 221.208.208.101 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 44.139.107.99 [ 44.139.107.99 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: :Amateur Radio Digital Communications&lt;br /&gt;OrgID: : ARDC&lt;br /&gt;Address:&lt;br /&gt;City:&lt;br /&gt;StateProv:&lt;br /&gt;PostalCode:&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026 ---------&lt;br /&gt;IP Address : 110.223.103.15 [ 110.223.103.15 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 221.208.208.100 [ 221.208.208.100 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 16.190.180.16 [ 16.190.180.16 ]&lt;br /&gt;ISP : HEWLETT-PACKARD COMPANY&lt;br /&gt;Organization : Hewlett-Packard Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Palo Alto, CA 94304&lt;br /&gt;Latitude : 37°37'62" North&lt;br /&gt;Longitude : 122°18'26" West&lt;br /&gt;&lt;br /&gt;IP Address : 122.43.240.241 [ 122.43.240.241 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : POWERCOMM&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 214.174.173.142 [ 214.174.173.142 ]&lt;br /&gt;ISP : Naval Ocean Systems Center&lt;br /&gt;Organization : Naval Ocean Systems Center&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 155.164.42.223 [ 155.164.42.223 ]&lt;br /&gt;ISP : Cingular Wireless II, LLC&lt;br /&gt;Organization : Cingular Wireless II, LLC&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 77.148.5.226 [ 77.148.5.226 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : freenet Cityline GmbH&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Kiel, 10 -&lt;br /&gt;Latitude : 54°33'33" North&lt;br /&gt;Longitude : 10°13'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 142.217.35.43 [ 142-217-35-43.telebecinternet.net ]&lt;br /&gt;ISP : Telebec&lt;br /&gt;Organization : Telebec&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Scarborough, ON -&lt;br /&gt;Latitude : 43°75'00" North&lt;br /&gt;Longitude : 79°20'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 91.81.75.23 [ 91.81.75.23 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Vodafone Omnitel N.V.&lt;br /&gt;Location : IT, Italy&lt;br /&gt;City : Ivrea, 12 -&lt;br /&gt;Latitude : 45°46'67" North&lt;br /&gt;Longitude : 7°86'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.238.193 [ S0106000cf1e85077.cg.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB -&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 47.8.89.165 [ h165s89a8n47.user.nortelnetworks.com ]&lt;br /&gt;ISP : Bell-Northern Research&lt;br /&gt;Organization : Nortel Networks&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Ottawa, ON k1y4h7&lt;br /&gt;Latitude : 45°41'67" North&lt;br /&gt;Longitude : 75°70'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 133.94.112.4 [ 133.94.112.4 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;OrgName: : Japan Network Information Center&lt;br /&gt;OrgID: : JNIC&lt;br /&gt;Address: : Kokusai-kougyou-Kanda Bldg 6F&lt;br /&gt;Address: : 2-3-4 Uchikanda&lt;br /&gt;City: : Chiyoda-ku&lt;br /&gt;StateProv: : Tokyo&lt;br /&gt;PostalCode: : 101-0047&lt;br /&gt;Country: : JP&lt;br /&gt;&lt;br /&gt;IP Address : 33.14.45.142 [ 33.14.45.142 ]&lt;br /&gt;ISP : Naval Ocean Systems Center&lt;br /&gt;Organization : Naval Ocean Systems Center&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 175.71.14.149 [ 175.71.14.149 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 121.135.156.114 [ 121.135.156.114 ]&lt;br /&gt;ISP : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 210.79.52.144 [ 210.79.52.144 ]&lt;br /&gt;ISP : Traced to Auckland, New Zealand and lost&lt;br /&gt;&lt;br /&gt;IP Address : 44.139.107.99 [ 44.139.107.99 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Amateur Radio Digital Communications&lt;br /&gt;OrgID: : ARDC&lt;br /&gt;Address:&lt;br /&gt;City:&lt;br /&gt;StateProv:&lt;br /&gt;PostalCode:&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 82.26.217.87 [ client-82-26-217-87.glfd.adsl.virgin.net ]&lt;br /&gt;ISP : NTL Internet&lt;br /&gt;Organization : NTL Internet&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : Rochdale, L2 -&lt;br /&gt;Latitude : 53°61'67" North&lt;br /&gt;Longitude : 2°15'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 214.71.189.59 [ 214.71.189.59 ]&lt;br /&gt;ISP : Naval Ocean Systems Center&lt;br /&gt;Organization : Naval Ocean Systems Center&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 57.14.29.60 [ 57.14.29.60 ]&lt;br /&gt;ISP : SITA-Societe Internationale de Telecommunications&lt;br /&gt;Organization : SITA-Societe Internationale de Telecommunications&lt;br /&gt;Location : EU, Europe&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 47°00'00" North&lt;br /&gt;Longitude : 8°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.135.158.111 [ voip-69-135-158-111.neo.rr.com ]&lt;br /&gt;ISP : Road Runner&lt;br /&gt;Organization : Road Runner&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 121.110.92.53 [ KD121110092053.ppp-bb.dion.ne.jp ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : KDDI Corporation&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : Tokyo, 40 -&lt;br /&gt;Latitude : 35°68'50" North&lt;br /&gt;Longitude : 139°75'14" East&lt;br /&gt;&lt;br /&gt;IP Address : 177.119.235.34 [ 177.119.235.34 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 174.28.137.177 [ 174.28.137.177 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 142.61.198.197 [ 142.61.198.197 ]&lt;br /&gt;ISP : Canadian Research Network&lt;br /&gt;Organization : Canadian Research Network&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Toronto, ON m5s3j1&lt;br /&gt;Latitude : 43°66'67" North&lt;br /&gt;Longitude : 79°41'68" West&lt;br /&gt;&lt;br /&gt;IP Address : 216.165.129.157 [ ns6.dns.tds.net ]&lt;br /&gt;ISP : TDS TELECOM&lt;br /&gt;Organization : TDS TELECOM&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Madison, WI 53717&lt;br /&gt;Latitude : 43°07'37" North&lt;br /&gt;Longitude : 89°52'74" West&lt;br /&gt;&lt;br /&gt;IP Address : 178.95.193.126 [ 178.95.193.126 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 26.198.93.126 [ 26.198.93.126 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : DoD Network Information Center&lt;br /&gt;OrgID: : DNIC&lt;br /&gt;Address: : 3990 E. Broad Street&lt;br /&gt;City: : Columbus&lt;br /&gt;StateProv: : OH&lt;br /&gt;PostalCode: : 43218&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 209.197.186.202 [ hs-scarlett-209197186202.3web.net ]&lt;br /&gt;ISP : Cybersurf&lt;br /&gt;Organization : 3web Corp.&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB t2e7p1&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 139.186.84.121 [ 139.186.84.121 ]&lt;br /&gt;ISP : No Record (Unknown) No Trace Whatsoever&lt;br /&gt;&lt;br /&gt;IP Address : 161.224.174.101 [ 161.224.174.101 ]&lt;br /&gt;ISP : Buckeye Pipe Line Company&lt;br /&gt;Organization : Buckeye Pipe Line Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Emmaus, PA 18049&lt;br /&gt;Latitude : 40°51'89" North&lt;br /&gt;Longitude : 75°50'13" West&lt;br /&gt;&lt;br /&gt;IP Address : 182.148.106.18 [ 182.148.106.18 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 108.85.32.236 [ 108.85.32.236 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 183.200.235.254 [ 183.200.235.254 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 118.242.111.243 [ 118.242.111.243 ]&lt;br /&gt;OrgName: : Asia Pacific Network Information Centre&lt;br /&gt;OrgID: : APNIC&lt;br /&gt;Address: : PO Box 2131&lt;br /&gt;City: : Milton&lt;br /&gt;StateProv: : QLD&lt;br /&gt;PostalCode: : 4064&lt;br /&gt;Country: : AU&lt;br /&gt;&lt;br /&gt;IP Address : 214.84.88.214 [ 214.84.88.214 ]&lt;br /&gt;ISP : Naval Ocean Systems Center&lt;br /&gt;Organization : Naval Ocean Systems Center&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----Port 1027 -----------&lt;br /&gt;IP Address : 24.64.238.193 [ S0106000cf1e85077.cg.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB -&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 82.166.13.50 [ 82-166-13-50.barak-online.net ]&lt;br /&gt;ISP : Barak I.T.C&lt;br /&gt;Organization : Barak I.T.C&lt;br /&gt;Location : IL, Israel&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 31°50'00" North&lt;br /&gt;Longitude : 34°75'00" East&lt;br /&gt;&lt;br /&gt;----Port 1028 -----------&lt;br /&gt;IP Address : 24.64.238.193 [ S0106000cf1e85077.cg.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB -&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;----Port 21 -----------&lt;br /&gt;IP Address : 202.108.12.7 [ 202.108.12.7 ]&lt;br /&gt;ISP : CNCGROUP Beijing province network&lt;br /&gt;Organization : CNCGROUP Beijing Province Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 22 -----------&lt;br /&gt;IP Address : 212.204.181.15 [ cc573055-b.wolve1.fr.home.nl ]&lt;br /&gt;ISP : Essent Kabelcom B.V.&lt;br /&gt;Organization : Essent Kabelcom B.V. B.V.&lt;br /&gt;Location : NL, Netherlands&lt;br /&gt;City : Nijmegen, 03 -&lt;br /&gt;Latitude : 51°83'33" North&lt;br /&gt;Longitude : 5°86'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 61.146.178.13 [ 61.146.178.13 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : ChinaNet Guangdong Province Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Guangzhou, 30 -&lt;br /&gt;Latitude : 23°11'67" North&lt;br /&gt;Longitude : 113°25'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 65.19.156.160 [ 65.19.156.160 ]&lt;br /&gt;ISP : Hurricane Electric&lt;br /&gt;Organization : Joe's Web Hosting&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : Osaka, 32 -&lt;br /&gt;Latitude : 34°66'67" North&lt;br /&gt;Longitude : 135°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 202.106.62.52 [ 202.106.62.52 ]&lt;br /&gt;ISP : CNCGROUP Beijing province network&lt;br /&gt;Organization : CNCGROUP Beijing Province Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 208.115.34.232 [ 208.115.34.232 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Bocacom.net LLC&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Boca Raton, FL 33431&lt;br /&gt;Latitude : 26°38'18" North&lt;br /&gt;Longitude : 80°10'46" West&lt;br /&gt;&lt;br /&gt;----Port 25 -----------&lt;br /&gt;IP Address : 61.31.167.78 [ 61-31-167-78.dynamic.tfn.net.tw ]&lt;br /&gt;ISP : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Organization : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;----Port 1080 ----------&lt;br /&gt;IP Address : 125.65.76.15 [ 125.65.76.15 ]&lt;br /&gt;ISP : CHINANET Sichuan province network&lt;br /&gt;Organization : SC-MY-XIWEISHUMA-LYD&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mianyang, 32 -&lt;br /&gt;Latitude : 31°46'67" North&lt;br /&gt;Longitude : 104°76'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 222.239.255.43 [ 222.239.255.43 ]&lt;br /&gt;ISP : Hanaro Telecom, Inc.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seoul, 11 -&lt;br /&gt;Latitude : 37°56'64" North&lt;br /&gt;Longitude : 126°99'97" East&lt;br /&gt;&lt;br /&gt;----Port 1433 ----------&lt;br /&gt;IP Address : 60.248.124.139 [ 60-248-124-139.HINET-IP.hinet.net ]&lt;br /&gt;ISP : CHTD, Chunghwa Telecom Co.,Ltd.&lt;br /&gt;Organization : Chunghwa Telecom Data communication Business Group&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.149.1.231 [ adsl-69-149-1-231.dsl.rcsntx.swbell.net ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : SBC Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 218.28.119.230 [ pc0.zz.ha.cn ]&lt;br /&gt;ISP : CNCGROUP Henan province network&lt;br /&gt;Organization : CNCGROUP Henan province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Henan, 24 -&lt;br /&gt;Latitude : 37°89'97" North&lt;br /&gt;Longitude : 112°18'72" East&lt;br /&gt;&lt;br /&gt;----Port 1434 ----------&lt;br /&gt;IP Address : 61.242.244.143 [ 61.242.244.143 ]&lt;br /&gt;ISP : China United Telecommunications Corporation&lt;br /&gt;Organization : China United Telecommunications Corporation&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.130.68.206 [ 221.130.68.206 ]&lt;br /&gt;ISP : China Mobile Communications Corporation&lt;br /&gt;Organization : China Mobile Communications Corporation - jiangsu&lt;br /&gt;Location : CN, China&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 35°00'00" North&lt;br /&gt;Longitude : 105°00'00" East&lt;br /&gt;&lt;br /&gt;----Port 2967 -----------&lt;br /&gt;IP Address : 62.43.240.58 [ 62.43.240.58 ]&lt;br /&gt;ISP : ONO&lt;br /&gt;Organization : ONO&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Madrid, 29 -&lt;br /&gt;Latitude : 40°40'00" North&lt;br /&gt;Longitude : 3°68'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 64.194.57.21 [ ims-64-194-57-21.imsday.com ]&lt;br /&gt;ISP : Level 3 Communications&lt;br /&gt;Organization : Time Warner Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houston, TX -&lt;br /&gt;Latitude : 29°77'55" North&lt;br /&gt;Longitude : 95°41'52" West&lt;br /&gt;&lt;br /&gt;IP Address : 218.66.104.217 [ 218.66.104.217 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Data Communication Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;---Port 2968 ----------&lt;br /&gt;IP Address : 69.22.217.135 [ user-12hdmc7.cable.mindspring.com ]&lt;br /&gt;ISP : EarthLink&lt;br /&gt;Organization : EarthLink&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cliffside Park, NJ 07010&lt;br /&gt;Latitude : 40°82'03" North&lt;br /&gt;Longitude : 73°98'71" West&lt;br /&gt;&lt;br /&gt;----Port 3128 ---------&lt;br /&gt;IP Address : 87.118.118.98 [ ns.km31021.keymachine.de ]&lt;br /&gt;ISP : Keyweb AG&lt;br /&gt;Organization : Keyweb AG IP Network&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Erfurt, 15 -&lt;br /&gt;Latitude : 50°98'33" North&lt;br /&gt;Longitude : 11°03'33" East&lt;br /&gt;&lt;br /&gt;----Port 4899 ---------&lt;br /&gt;IP Address : 61.153.155.189 [ 61.153.155.189 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-ZJ Ningbo node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Ningbo, 02 -&lt;br /&gt;Latitude : 29°87'50" North&lt;br /&gt;Longitude : 121°54'19" East&lt;br /&gt;&lt;br /&gt;IP Address : 59.163.49.6 [ 59.163.49.6.static.vsnl.net.in ]&lt;br /&gt;ISP : Videsh Sanchar Nigam Ltd - India.&lt;br /&gt;Organization : Videsh Sanchar Nigam Ltd&lt;br /&gt;Location : IN, India&lt;br /&gt;City : Bombay, 16 -&lt;br /&gt;Latitude : 18°97'50" North&lt;br /&gt;Longitude : 72°82'58" East&lt;br /&gt;&lt;br /&gt;----Port 5900 ----------&lt;br /&gt;IP Address : 82.101.190.13 [ 82.101.190.13 ]&lt;br /&gt;ISP : IP-ADSL-ALGER&lt;br /&gt;Organization : IP-ADSL-ALGER&lt;br /&gt;Location : DZ, Algeria&lt;br /&gt;City : Alger, 01 -&lt;br /&gt;Latitude : 36°76'31" North&lt;br /&gt;Longitude : 3°05'06" East&lt;br /&gt;&lt;br /&gt;IP Address : 222.216.28.178 [ 222.216.28.178 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;IP Address : 211.116.157.35 [ 211.116.157.35 ]&lt;br /&gt;ISP : KRNIC&lt;br /&gt;Organization : NEORO COM&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.95.184.104 [ 218.95.184.104 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET ningxia province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 7212 -------------&lt;br /&gt;IP Address : 60.213.45.62 [ 60.213.45.62 ]&lt;br /&gt;ISP : CNCGROUP Shandong province network&lt;br /&gt;Organization : CNCGROUP Shandong province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Jinan, 25 -&lt;br /&gt;Latitude : 36°66'83" North&lt;br /&gt;Longitude : 116°99'72" East&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity -----------&lt;br /&gt;IP Activity : Surfed port 80 and attacked through port 1080&lt;br /&gt;IP Address : 222.217.221.214 [ 222.217.221.214 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;IP Activity : Surfed port 80&lt;br /&gt;IP Address : 87.118.118.98 [ ns.km31021.keymachine.de ]&lt;br /&gt;ISP : Keyweb AG&lt;br /&gt;Organization : Keyweb AG IP Network&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Erfurt, 15 -&lt;br /&gt;Latitude : 50°98'33" North&lt;br /&gt;Longitude : 11°03'33" East&lt;br /&gt;&lt;br /&gt;IP Activity : Surfed port 80&lt;br /&gt;IP Address : 213.55.79.250 [ 213.55.79.250 ]&lt;br /&gt;ISP : Ethiopian Telecommuncation Corporation&lt;br /&gt;Organization : Ethiopian Telecommunication corporation&lt;br /&gt;Location : ET, Ethiopia&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 8°00'00" North&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-464372168726400506?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/464372168726400506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=464372168726400506' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/464372168726400506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/464372168726400506'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-28-2007.html' title='Cyber Center Report - October 28, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-6629592155037895209</id><published>2007-10-29T07:47:00.000-04:00</published><updated>2007-10-29T08:15:13.226-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='DMZ'/><category scheme='http://www.blogger.com/atom/ns#' term='attack analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='intrusion'/><category scheme='http://www.blogger.com/atom/ns#' term='IPS'/><category scheme='http://www.blogger.com/atom/ns#' term='honey pot'/><category scheme='http://www.blogger.com/atom/ns#' term='Intranet'/><title type='text'>Information about the Honey Pot</title><content type='html'>Information about the Honey Pot&lt;br /&gt;&lt;br /&gt;Several people have asked about more information regarding our Honey pot. We have deployed our honey pot directly connected to the Internet with a non-descript basic webpage. In doing so, we are exposed to every computer probe and attack that finds its way to our IP. We are using turnkey cyber center software from Black Lab Security Systems that monitors and protects a standard workstation or server used as a honey pot. We do our best to protect the IP address of the honey pot to protect the integrity of what is detected. Cyber-probes and -attacks can be monitor in near-real time mode and quickly analyzed from the forensics evidenced gathered.&lt;br /&gt;&lt;br /&gt;In simplest terms, enterprises would benefit from using a honey pot in on company registered IPs to analyze what probes and attacks are (1) finding enterprise systems directly connected to the Internet, (2) intruding enterprise’s demilitarized zone (DMZ), and (3) intruding an enterprises internal network or intranet.&lt;br /&gt;&lt;br /&gt;Internal Network&lt;br /&gt;Attacks to the internal network are the most serious and immediate action should be considered. Attacks, scans, and probes can come from both internal (e.g., the insider threat) or external.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-6629592155037895209?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/6629592155037895209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=6629592155037895209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6629592155037895209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6629592155037895209'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/information-about-honey-pot.html' title='Information about the Honey Pot'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-4747955929691619216</id><published>2007-10-28T22:01:00.000-04:00</published><updated>2007-10-29T08:11:52.095-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 27, 2007</title><content type='html'>BLSS Cyber Center Report - 27 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;IMPORTANT - This report identifies the most significant computers suddenly broadcasting over the Internet.&lt;br /&gt;&lt;br /&gt;China and Korea continue to probe/attack the U.S. with a new level of tenacity. All previous probes/attacks on China and Korean IPs continue on all reported ports. Last night's probes/attacks have reached an all-time high of new and significant computers now broadcasting on port 1026. Never before has the BLSS Cyber Center, detected so many "significant" computers, to suddenly start broadcasting (almost) at one time over port 1026. The computers now broadcasting on Port 1026 are the following:&lt;br /&gt;&lt;br /&gt;1) Chevron Corporation&lt;br /&gt;2) The British Petroleum Company&lt;br /&gt;3) Hewlett-Packard&lt;br /&gt;4) Wageningen University and Research Centre (NetherLands)&lt;br /&gt;5) Two Computers Recorded as the property of the Department Of Defense&lt;br /&gt;(DoD)&lt;br /&gt;6) The "Societe Internationale de Telecommunications" (Europe)&lt;br /&gt;7) The NIB (National Internet Backbone) Of India&lt;br /&gt;8) The Japan Network Information Center- Japan&lt;br /&gt;9) The Government of the Province of Ontario- Canada&lt;br /&gt;10) The Cable And Wireless System Of Panama&lt;br /&gt;11) Two computers that cannot be identified, which most likely belong to a government agency.&lt;br /&gt;12) One computer which was traced to , but the trace was lost on the African Continent.&lt;br /&gt;&lt;br /&gt;The other significant computer, is America On Line (AOL) which is now broadcasting over port 5900.&lt;br /&gt;&lt;br /&gt;Other significant news is that CHINA IS AWARE of the BLSS Honey Pot and is now "surfing" probing and attacking the BLSS Honey Pot. China has NOT been successful (so far) utilizing their methods/programs against the BLSS Honey Pot. The BLSS Honey Pot is stopping all attacks by China. The Chinese IP is 219.153.5.169 located in Shanghai, China.&lt;br /&gt;&lt;br /&gt;Other additional probes on port 1026 include Thailand, India, U.S., Japan, and the Ukraine. The Internet Assigned Numbers Authority (IANA) also probed port 1026 three times last night. Port 22; China (new site), Taiwan (new site). Port 1433; China (new site), Korea (new site). Port 1434; China (2 new sites). Port 4899; U.S. (new site). Port 5168; China (new site). Port 5900; U.S. (2 new sites - AOL reported above and Mikrotec Internet Services), Greece (new site). Honey Pot Activity; China "surfing" and unsuccessfully attacking the BLSS Honey Pot (reported above), One other "surf" located in the U.S. (Utah). No attack from the Utah "surf".&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026 ----------------&lt;br /&gt;IP Address : 203.151.151.246 [ 203.151.151.246 ]&lt;br /&gt;ISP : Internet Thailand Company Limited&lt;br /&gt;Organization : Internet Thailand Company Limited&lt;br /&gt;Location : TH, Thailand&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 15°00'00" North&lt;br /&gt;Longitude : 100°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 64.184.56.105 [ ip56-105.dyn.comteck.com ]&lt;br /&gt;ISP : Indiana Fiber Network, LLC&lt;br /&gt;Organization : Sweetser Telephone Co.&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Sweetser, IN 46987&lt;br /&gt;Latitude : 40°56'95" North&lt;br /&gt;Longitude : 85°76'68" West&lt;br /&gt;&lt;br /&gt;IP Address : 63.28.160.72 [ 1Cust72.an4.nyc41.da.uu.net ]&lt;br /&gt;ISP : UUNET Technologies&lt;br /&gt;Organization : UUNET Technologies&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Ashburn, VA 20147&lt;br /&gt;Latitude : 39°03'35" North&lt;br /&gt;Longitude : 77°48'38" West&lt;br /&gt;&lt;br /&gt;IP Address : 61.16.186.68 [ hw-static-68-186-16-61.direct.net.in ]&lt;br /&gt;ISP : Direct Internet&lt;br /&gt;Organization : Hotwire&lt;br /&gt;Location : IN, India&lt;br /&gt;City : New Delhi, 07 -&lt;br /&gt;Latitude : 28°60'00" North&lt;br /&gt;Longitude : 77°20'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 97.127.86.68 [ 97.127.86.68 ]&lt;br /&gt;ISP : No Record (Not recorded)&lt;br /&gt;&lt;br /&gt;IP Address : 61.119.81.22 [ 61.119.81.22 ]&lt;br /&gt;ISP : Nippon Telecommunication Network Co.,Ltd.&lt;br /&gt;Organization : NTT Communications Corporation&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 174.220.153.83 [ 174.220.153.83 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv : CA&lt;br /&gt;PostalCode : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 137.224.244.14 [ 137.224.244.14 ]&lt;br /&gt;ISP : Wageningen University and Research Centre&lt;br /&gt;Organization : Wageningen University and Research Centre&lt;br /&gt;Location : NL, Netherlands&lt;br /&gt;City : Wageningen, 03 -&lt;br /&gt;Latitude : 51°96'67" North&lt;br /&gt;Longitude : 5°66'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 161.103.43.111 [ 161.103.43.111 ]&lt;br /&gt;ISP : The British Petroleum Company p.l.c (BP)&lt;br /&gt;Organization : The British Petroleum Company p.l.c (BP)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cleveland, OH 44128&lt;br /&gt;Latitude : 41°43'79" North&lt;br /&gt;Longitude : 81°53'66" West&lt;br /&gt;&lt;br /&gt;IP Address : 30.126.167.170 [ 30.126.167.170 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : DoD Network Information Center&lt;br /&gt;OrgID: : DNIC&lt;br /&gt;Address: : 3990 E. Broad Street&lt;br /&gt;City: : Columbus&lt;br /&gt;StateProv: : OH&lt;br /&gt;PostalCode: : 43218&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 133.210.238.95 [ 133.210.238.95 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;OrgName: : Japan Network Information Center&lt;br /&gt;OrgID: : JNIC&lt;br /&gt;Address: : Kokusai-kougyou-Kanda Bldg 6F&lt;br /&gt;Address: : 2-3-4 Uchikanda&lt;br /&gt;City: : Chiyoda-ku&lt;br /&gt;StateProv : Tokyo&lt;br /&gt;PostalCode : 101-0047&lt;br /&gt;Country: : JP&lt;br /&gt;&lt;br /&gt;IP Address : 190.34.233.95 [ 190.34.233.95 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Cable &amp;amp; Wireless Panama&lt;br /&gt;Location : PA, Panama&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 9°00'00" North&lt;br /&gt;Longitude : 80°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 36.186.62.69 [ 36.186.62.69 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 105.113.251.184 [ 105.113.251.184 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 191.186.213.173 [ 191.186.213.173 ]&lt;br /&gt;ISP : No Record (Not Recorded)&lt;br /&gt;&lt;br /&gt;IP Address : 57.236.39.178 [ 57.236.39.178 ]&lt;br /&gt;ISP : SITA-Societe Internationale de Telecommunications&lt;br /&gt;Organization : SITA-Societe Internationale de Telecommunications&lt;br /&gt;Location : EU, Europe&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 47°00'00" North&lt;br /&gt;Longitude : 8°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 146.29.139.39 [ 146.29.139.39 ]&lt;br /&gt;ISP : Chevron Corporation&lt;br /&gt;Organization : Chevron Corporation&lt;br /&gt;Location : US, United States&lt;br /&gt;City : San Ramon, CA 94583&lt;br /&gt;Latitude : 37°78'06" North&lt;br /&gt;Longitude : 121°99'04" West&lt;br /&gt;&lt;br /&gt;IP Address : 31.28.22.227 [ 31.28.22.227 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 117.243.53.225 [ 117.243.53.225 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : NIB (National Internet Backbone)&lt;br /&gt;Location : IN, India&lt;br /&gt;City : New Delhi, 07 -&lt;br /&gt;Latitude : 28°60'00" North&lt;br /&gt;Longitude : 77°20'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 142.106.73.19 [ 142.106.73.19 ]&lt;br /&gt;ISP : Government of the Province of Ontario&lt;br /&gt;Organization : Government of the Province of Ontario&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Toronto, ON m5h3b7&lt;br /&gt;Latitude : 43°66'67" North&lt;br /&gt;Longitude : 79°41'68" West&lt;br /&gt;&lt;br /&gt;IP Address : 16.180.25.196 [ 16.180.25.196 ]&lt;br /&gt;ISP : HEWLETT-PACKARD COMPANY&lt;br /&gt;Organization : Hewlett-Packard Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Palo Alto, CA 94304&lt;br /&gt;Latitude : 37°37'62" North&lt;br /&gt;Longitude : 122°18'26" West&lt;br /&gt;&lt;br /&gt;IP Address : 41.29.76.81 [ 41.29.76.81 ]&lt;br /&gt;ISP : No Record (Not Recorded), But known to be somewhere in Africa&lt;br /&gt;: Was Directed To The AfriNIC Whois server&lt;br /&gt;&lt;br /&gt;IP Address : 77.91.184.1 [ 77-91-184-1.client.telesystems.ua ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Telesystems of Ukraine LLC&lt;br /&gt;Location : UA, Ukraine&lt;br /&gt;City : Kiev, 13 -&lt;br /&gt;Latitude : 50°43'33" North&lt;br /&gt;Longitude : 30°51'67" East&lt;br /&gt;&lt;br /&gt;----Port 22 ------------------&lt;br /&gt;IP Address : 210.202.199.132 [&lt;br /&gt;TC210-202-199-132.vdslpro.static.apol.com.tw ]&lt;br /&gt;ISP : Asia Pacific On-line Services Inc.&lt;br /&gt;Organization : Jeng Wu Jie Automatous Co., Ltd.&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taichung, 04 -&lt;br /&gt;Latitude : 24°14'33" North&lt;br /&gt;Longitude : 120°68'14" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.92.205.106 [ 218.92.205.106 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 25 -------------------&lt;br /&gt;IP Address : 125.225.22.110 [ 125-225-22-110.dynamic.hinet.net ]&lt;br /&gt;ISP : CHTD, Chunghwa Telecom Co.,Ltd.&lt;br /&gt;Organization : Chunghwa Telecom Data communication Business Group&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;----Port 1433 ----------------&lt;br /&gt;IP Address : 210.51.187.88 [ 210.51.187.88 ]&lt;br /&gt;ISP : CNCGROUP IP network&lt;br /&gt;Organization : Beijing YiZhuang IDC of China Netcom&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.38.56.170 [ 218.38.56.170 ]&lt;br /&gt;ISP : KRNIC&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Port 1434 ----------------&lt;br /&gt;IP Address : 218.108.70.246 [ 218.108.70.246 ]&lt;br /&gt;ISP : WASU TV &amp;amp; Communication Holding Co.,Ltd.&lt;br /&gt;Organization : wangJiangFeng&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Chaoyang, 19 -&lt;br /&gt;Latitude : 41°57'03" North&lt;br /&gt;Longitude : 120°45'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 60.175.101.20 [ 60.175.101.20 ]&lt;br /&gt;ISP : CHINANET Anhui province network&lt;br /&gt;Organization : CHINANET Anhui province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hefei, 01 -&lt;br /&gt;Latitude : 31°86'39" North&lt;br /&gt;Longitude : 117°28'08" East&lt;br /&gt;&lt;br /&gt;----Port 4899 ----------------&lt;br /&gt;IP Address : 76.105.111.122 [ c-76-105-111-122.hsd1.ga.comcast.net ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 5168 ----------------&lt;br /&gt;IP Address : 58.246.107.14 [ 58.246.107.14 ]&lt;br /&gt;ISP : CNC Group ShangHai province network&lt;br /&gt;Organization : CNC Group ShangHai province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;----Port 5900 -----------------&lt;br /&gt;IP Address : 172.201.222.7 [ ACC9DE07.ipt.aol.com ]&lt;br /&gt;ISP : America Online&lt;br /&gt;Organization : America Online&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 80.76.56.66 [ dslcustomer66.vivodi.gr ]&lt;br /&gt;ISP : Vivodi Telecommunications S.A.&lt;br /&gt;Organization : Vivodi Telecommunications S.A.&lt;br /&gt;Location : GR, Greece&lt;br /&gt;City : Athens, 35 -&lt;br /&gt;Latitude : 37°98'33" North&lt;br /&gt;Longitude : 23°73'32" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.176.25.80 [ hld-dsl-69-176-25-80.mis.net ]&lt;br /&gt;ISP : Mikrotec Internet Services&lt;br /&gt;Organization : Mikrotec Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Lexington, KY 40505&lt;br /&gt;Latitude : 38°06'15" North&lt;br /&gt;Longitude : 84°45'66" West&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity ---------------&lt;br /&gt;IP Address : 219.153.5.169 [&lt;br /&gt;169.5.153.219.broad.cq.cq.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Data Communication Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 216.83.145.130 [ 216.83.145.130.afcity.net ]&lt;br /&gt;ISP : Fibernet Corporation&lt;br /&gt;Organization : American Fork City&lt;br /&gt;Location : US, United States&lt;br /&gt;City : American Fork, UT 84003&lt;br /&gt;Latitude : 40°39'30" North&lt;br /&gt;Longitude : 111°78'38" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-4747955929691619216?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/4747955929691619216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=4747955929691619216' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/4747955929691619216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/4747955929691619216'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-27-2007.html' title='Cyber Center Report - October 27, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-2742009771902467814</id><published>2007-10-28T21:59:00.000-04:00</published><updated>2007-10-29T08:12:27.976-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 26, 2007</title><content type='html'>BLSS Cyber Center Report - 26 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Last night's probes/attacks were just as consistent and with the same sustained frequency as the 25 October 2005 BLSS Cyber Center Report. The severity and frequency of all previously reported probes/attacks (on all reported ports), from China and Korea remains consistent across the Internet.&lt;br /&gt;&lt;br /&gt;One new IP in China (221.194.46.204) is tenacious in it's continuous probing of port 7212. The frequency is so high, that 221.194.46.204 performs a probe every 3-4 minutes.&lt;br /&gt;&lt;br /&gt;New activity on Port 1026; The Internet Assigned Number Authority (IANA), performed 4 probes last night, with 4 different (new) IP addresses.&lt;br /&gt;&lt;br /&gt;Two IP addresses recorded as the property of the Department Of Defense (DoD), located somewhere (approximately) in Colorado were detected probing on port 1026. One computer with an unknown IP (not recorded) was detected probing on port 1026. Again, it has been our experience that unknown IPs (not recorded) are the property of some government agency. One computer that is recorded to be within Apple Computer Corporation was detected probing port 1026. Additional probes detected on Port 1026 were from U.S. (4 other new sites), New Zealand (new site), Slovenia (new site), Canada (2 new sites), Germany (new site), Japan (new site), Australia (new site). Port 1027; Canada (new site). Port 1028; Canada (new site). Port 22; Philippines (new site), U.S. (new site).&lt;br /&gt;&lt;br /&gt;Port 1433; China (2 new sites), Korea (new site), Port 1434; China (2 new sites). Port 2967; China (new site). Port 5900; Sweden (new site), China (new site), France (2 new sites). Port 7212; China (one new site, which was discussed above). Honey Port Activity; No attacks last night on the BLSS Honey Port. The BLSS Honey Pot was "surfed" by one IP in the U.S., and one IP in Spain from a University located in Madrid.&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026 ---------------&lt;br /&gt;IP Address : 23.102.102.67 [ 23.102.102.67 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 131.239.20.104 [ host-131-239-20-104.customer.veroxity.net ]&lt;br /&gt;ISP : Veroxity Technology Partners&lt;br /&gt;Organization : Veroxity Technology Partners&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Newtonville, MA 02460&lt;br /&gt;Latitude : 42°35'22" North&lt;br /&gt;Longitude : 71°20'98" West&lt;br /&gt;&lt;br /&gt;IP Address : 106.201.119.31 [ 106.201.119.31 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 138.211.173.87 [ 138.211.173.87 ]&lt;br /&gt;ISP : WAIARI&lt;br /&gt;Organization : WAIARI&lt;br /&gt;Location : NZ, New Zealand&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 41°00'00" South&lt;br /&gt;Longitude : 174°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 22.89.119.186 [ 22.89.119.186 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : DoD Network Information Center&lt;br /&gt;OrgID: : DNIC&lt;br /&gt;Address: : 3990 E. Broad Street&lt;br /&gt;City: : Columbus&lt;br /&gt;StateProv: : OH&lt;br /&gt;PostalCode: : 43218&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 22.216.206.127 [ 22.216.206.127 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : DoD Network Information Center&lt;br /&gt;OrgID: : DNIC&lt;br /&gt;Address: : 3990 E. Broad Street&lt;br /&gt;City: : Columbus&lt;br /&gt;StateProv: : OH&lt;br /&gt;PostalCode: : 43218&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 75.35.178.112 [ 75.35.178.112 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Aquila&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Overland Park, KS 66214&lt;br /&gt;Latitude : 38°96'43" North&lt;br /&gt;Longitude : 94°71'35" West&lt;br /&gt;&lt;br /&gt;IP Address : 12.122.135.214 [ 12.122.135.214 ]&lt;br /&gt;ISP : AT&amp;amp;T WorldNet Services&lt;br /&gt;Organization : AT&amp;amp;T WorldNet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 153.5.22.199 [ cmb61-199.dial-up.arnes.si ]&lt;br /&gt;ISP : Slovenia&lt;br /&gt;Organization : Slovenia&lt;br /&gt;Location : SI, Slovenia&lt;br /&gt;City : Ljubljana, 04 -&lt;br /&gt;Latitude : 46°05'53" North&lt;br /&gt;Longitude : 14°51'44" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.138.179 [ S01060010dcf19f13.lb.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 171.61.227.28 [ 171.61.227.28 ]&lt;br /&gt;ISP : No Record (Unknown)&lt;br /&gt;&lt;br /&gt;IP Address : 213.69.88.54 [ 213.69.88.54 ]&lt;br /&gt;ISP : MCI Deutschland&lt;br /&gt;Organization : Gilat Europe GmbH&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Backnang, 01 -&lt;br /&gt;Latitude : 48°95'00" North&lt;br /&gt;Longitude : 9°43'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 180.254.222.130 [ 180.254.222.130 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 204.205.236.130 [ 204.205.236.130 ]&lt;br /&gt;ISP : Sprint&lt;br /&gt;Organization : Sprint&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Sprint&lt;br /&gt;OrgID: : SPRN&lt;br /&gt;Address: : 12502 Sunrise Valley Drive&lt;br /&gt;City: : Reston&lt;br /&gt;StateProv: : VA&lt;br /&gt;PostalCode: : 20196&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 37.69.229.31 [ 37.69.229.31 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 120.121.232.78 [ 120.121.232.78 ]&lt;br /&gt;OrgName: : Asia Pacific Network Information Centre&lt;br /&gt;OrgID: : APNIC&lt;br /&gt;Address: : PO Box 2131&lt;br /&gt;City: : Milton&lt;br /&gt;StateProv: : QLD&lt;br /&gt;PostalCode: : 4064&lt;br /&gt;Country: : AU&lt;br /&gt;&lt;br /&gt;IP Address : 17.115.18.103 [ 17.115.18.103 ]&lt;br /&gt;ISP : APPLE COMPUTER&lt;br /&gt;Organization : APPLE COMPUTER&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cupertino, CA 95014&lt;br /&gt;Latitude : 37°30'42" North&lt;br /&gt;Longitude : 122°09'46" West&lt;br /&gt;&lt;br /&gt;IP Address : 122.103.75.247 [ e3d247.BFL12.vectant.ne.jp ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : VECTANT Ltd.&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 66.97.29.3 [ 66.97.29.3 ]&lt;br /&gt;ISP : ORANO&lt;br /&gt;Organization : ORANO&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Toronto, ON m5c2x8&lt;br /&gt;Latitude : 43°66'67" North&lt;br /&gt;Longitude : 79°41'68" West&lt;br /&gt;&lt;br /&gt;----Port 1027 ----------------&lt;br /&gt;IP Address : 24.64.138.179 [ S01060010dcf19f13.lb.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1028 -----------------&lt;br /&gt;IP Address : 24.64.138.179 [ S01060010dcf19f13.lb.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 22 -----------------&lt;br /&gt;IP Address : 125.252.66.222 [ ip-125-252-66-222.asianetcom.net ]&lt;br /&gt;ISP : Asia Netcom Corporation&lt;br /&gt;Organization : Worldwide Technologies Ltd. / Digitel&lt;br /&gt;Location : PH, Philippines&lt;br /&gt;City : Asia, H3 -&lt;br /&gt;Latitude : 9°55'17" North&lt;br /&gt;Longitude : 122°51'75" East&lt;br /&gt;&lt;br /&gt;IP Address : 66.143.231.89 [ adsl-66-143-231-89.aasimsa.com ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : Rosa Hilda Andrade&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Columbus, KS 66725&lt;br /&gt;Latitude : 37°14'93" North&lt;br /&gt;Longitude : 94°88'93" West&lt;br /&gt;&lt;br /&gt;----Port 1433 ---------------&lt;br /&gt;IP Address : 218.26.89.141 [ 218.26.89.141 ]&lt;br /&gt;ISP : China Network Communications Group Corporation&lt;br /&gt;Organization : changzhi xxghw gov&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Changzhi, 24 -&lt;br /&gt;Latitude : 36°04'58" North&lt;br /&gt;Longitude : 113°04'42" East&lt;br /&gt;&lt;br /&gt;IP Address : 121.139.129.4 [ 121.139.129.4 ]&lt;br /&gt;ISP : Korea Telecom&lt;br /&gt;Organization : keieii(ju)&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 222.217.221.214 [ 222.217.221.214 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;----Port 1434 ----------------&lt;br /&gt;IP Address : 221.6.7.89 [ 221.6.7.89 ]&lt;br /&gt;ISP : CNC Group Jiangsu province network&lt;br /&gt;Organization : CNC Group Jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanjing, 04 -&lt;br /&gt;Latitude : 32°06'17" North&lt;br /&gt;Longitude : 118°77'78" East&lt;br /&gt;&lt;br /&gt;IP Address : 220.165.8.32 [ 220.165.8.32 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET Yunnan province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 2967 -----------------&lt;br /&gt;IP Address : 219.153.47.134 [&lt;br /&gt;134.47.153.219.broad.cq.cq.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Data Communication Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;----Port 5900 ---------------&lt;br /&gt;IP Address : 85.224.178.107 [&lt;br /&gt;c-6bb2e055.1111-1-64736c20.cust.bredbandsbolaget.se ]&lt;br /&gt;ISP : Bredbandsbolaget AB&lt;br /&gt;Organization : B2 customer network&lt;br /&gt;Location : SE, Sweden&lt;br /&gt;City : Hägersten, 26 -&lt;br /&gt;Latitude : 59°30'00" North&lt;br /&gt;Longitude : 17°96'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 124.132.3.222 [ 124.132.3.222 ]&lt;br /&gt;ISP : CNC Group Shandong province network&lt;br /&gt;Organization : CNC Group Shandong province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Jinan, 25 -&lt;br /&gt;Latitude : 36°66'83" North&lt;br /&gt;Longitude : 116°99'72" East&lt;br /&gt;&lt;br /&gt;IP Address : 91.121.24.215 [ ks39719.kimsufi.com ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : OVH SAS&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Roubaix, B4 -&lt;br /&gt;Latitude : 50°70'00" North&lt;br /&gt;Longitude : 3°16'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 83.113.65.59 [ ALyon-156-1-146-59.w83-113.abo.wanadoo.fr ]&lt;br /&gt;ISP : France Telecom&lt;br /&gt;Organization : France Telecom&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Lyon, B9 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 4°85'00" East&lt;br /&gt;&lt;br /&gt;----Port 7212 ---------------&lt;br /&gt;IP Address : 221.194.46.204 [ 221.194.46.204 ]&lt;br /&gt;ISP : CNCGROUP Hebei province network&lt;br /&gt;Organization : CNCGROUP Hebei province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hebei, 10 -&lt;br /&gt;Latitude : 39°88'97" North&lt;br /&gt;Longitude : 115°27'50" East&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity On Port 80 --------&lt;br /&gt;IP Address : 72.71.221.66 [ pool-72-71-221-66.cncdnh.east.verizon.net ]&lt;br /&gt;ISP : Verizon Internet Services&lt;br /&gt;Organization : Verizon Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 62.204.197.58 [ ccia-062-204-197-058.uned.es ]&lt;br /&gt;ISP : Universidad Nacional de Educacion a Distancia&lt;br /&gt;Organization : Universidad Nacional de Educacion a Distancia&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Madrid, 29 -&lt;br /&gt;Latitude : 40°40'00" North&lt;br /&gt;Longitude : 3°68'33" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-2742009771902467814?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/2742009771902467814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=2742009771902467814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/2742009771902467814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/2742009771902467814'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-26-2007.html' title='Cyber Center Report - October 26, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-8312043343595040855</id><published>2007-10-28T21:57:00.000-04:00</published><updated>2007-10-29T08:13:15.046-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 25, 2007</title><content type='html'>BLSS Cyber Center Report - 25 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Last night's probes/attacks were the worst we (BLSS), have detected since we started reporting Internet Activity. The severity and frequency of all previously reported probes/attacks (on all reported ports), from China, Korea, etc., has increased, along with more new IPs detected than ever previously reported. We have detected two new (active) ports, which are 8000 (China) and 23 (Germany). Port 1026; An interesting and astonishing observation, is that 5 separate probes were sent out from the Internet Assigned Numbers Authority (IANA) on five separate IP addresses. There were three IP addresses detected probing port 1026, which have no record. There is a high probability these three IPs (computers) belong to some government agency. An IP probe on port 1026 was detected from Ford Motor Company. An IP probe on port 1026 was detected from the U.S. Air Force. IP probes were detected on Port 1026 from Taiwan (new site), Argentina (new site), Germany (new site), Japan (new site), Venezuela (new site) and Canada (new site).&lt;br /&gt;Port 22; Japan (new site), Korea (2 new sites). Port 1027; Canada (2 new sites), Port 1028; Canada (2 new sites). Port 1433; U.S. (new site). Port 1434; U.S. (new site), China (new site), Mexico (new site). Port 2967; U.S.&lt;br /&gt;(new site), China (new site). Port 5168; China (new site). Port 5900; Mexico (new site), China (3 new sites), Spain (2 new sites), Korea (new site). Port 7212; Korea (new site). Honey Pot Activity; No attacks on BLSS Honey Pot. Two IPs "surfed" the Honey Pot via port 80; U.S. (new site), Latvia (new site).&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;------------------New ports detected ---------------------------&lt;br /&gt;&lt;br /&gt;----Port 8000 ----------&lt;br /&gt;IP Address : 218.3.134.250 [ 218.3.134.250 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Network Center of Fast China Shipbuilding institut&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Zhenjiang, 04 -&lt;br /&gt;Latitude : 32°20'92" North&lt;br /&gt;Longitude : 119°43'42" East&lt;br /&gt;&lt;br /&gt;----Port 23 -------------&lt;br /&gt;IP Address : 62.75.222.56 [ rom109.server4you.de ]&lt;br /&gt;ISP : intergenia AG&lt;br /&gt;Organization : SERVER4YOU Dedicated Server Hosting&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 51°00'00" North&lt;br /&gt;Longitude : 9°00'00" East&lt;br /&gt;&lt;br /&gt;-----------------Previously reportd ports with new IPs ------------&lt;br /&gt;&lt;br /&gt;----Port 22--------------&lt;br /&gt;IP Address : 121.1.133.193 [ w133193.ppp.asahi-net.or.jp ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : ASAHI Net,Inc.&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : Asahi, 04 -&lt;br /&gt;Latitude : 35°71'67" North&lt;br /&gt;Longitude : 140°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.234.32.131 [ 218.234.32.131 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : T&amp;amp;CSERVICE&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.153.221.29 [ 218.153.221.29 ]&lt;br /&gt;ISP : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Port 25 -------------&lt;br /&gt;IP Address : 122.136.45.2 [ 122.136.45.2 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : CNCGROUP Jilin province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Changchun, 05 -&lt;br /&gt;Latitude : 43°88'00" North&lt;br /&gt;Longitude : 125°32'28" East&lt;br /&gt;&lt;br /&gt;----Port 1026 -----------&lt;br /&gt;IP Address : 168.215.6.124 [ 168-215-6-124.static.twtelecom.net ]&lt;br /&gt;ISP : Time Warner Telecom&lt;br /&gt;Organization : Time Warner Telecom&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Littleton, CO 80124&lt;br /&gt;Latitude : 39°52'90" North&lt;br /&gt;Longitude : 104°90'50" West&lt;br /&gt;&lt;br /&gt;IP Address : 181.94.48.142&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 23.196.161.161&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 111.47.93.216 [ 111.47.93.216 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 31.105.131.203 [ 31.105.131.203 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 163.22.15.95 [ ip095.puli15.ncnu.edu.tw ]&lt;br /&gt;ISP : MOEC&lt;br /&gt;Organization : Taichung Changhua Nantou Regional Network&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taichung, 04 -&lt;br /&gt;Latitude : 24°14'33" North&lt;br /&gt;Longitude : 120°68'14" East&lt;br /&gt;&lt;br /&gt;IP Address : 79.237.38.69 [ 79.237.38.69 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Deutsche Telekom AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 51°00'00" North&lt;br /&gt;Longitude : 9°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 200.70.166.102 [ 200.70.166.102 ]&lt;br /&gt;ISP : Telefonica Data Argentina S.A.&lt;br /&gt;Organization : Telefonica Data Argentina S.A.&lt;br /&gt;Location : AR, Argentina&lt;br /&gt;City : Buenos Aires, 07 -&lt;br /&gt;Latitude : 34°58'75" South&lt;br /&gt;Longitude : 58°67'25" West&lt;br /&gt;&lt;br /&gt;IP Address : 136.74.8.184 [ 136.74.8.184 ]&lt;br /&gt;ISP : FORD MOTOR COMPANY&lt;br /&gt;Organization : FORD MOTOR COMPANY&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Dearborn, MI 48121&lt;br /&gt;Latitude : 42°31'27" North&lt;br /&gt;Longitude : 83°19'23" West&lt;br /&gt;&lt;br /&gt;IP Address : 151.231.90.82 [ 151.231.90.82 ]&lt;br /&gt;ISP : No Record Available&lt;br /&gt;&lt;br /&gt;IP Address : 161.196.217.237 [ 161.196.217.237 ]&lt;br /&gt;ISP : Compania Anonima Nacional de Telefonos de Venezuel&lt;br /&gt;Organization : Compania Anonima Nacional de Telefonos de Venezuel&lt;br /&gt;Location : VE, Venezuela&lt;br /&gt;City : Caracas, 25 -&lt;br /&gt;Latitude : 10°50'00" North&lt;br /&gt;Longitude : 66°91'67" West&lt;br /&gt;&lt;br /&gt;IP Address : 41.42.114.215 [ 41.42.114.215 ]&lt;br /&gt;ISP : No Record Available&lt;br /&gt;&lt;br /&gt;IP Address : 84.188.214.84 [ p54BCD654.dip.t-dialin.net ]&lt;br /&gt;ISP : Deutsche Telekom AG&lt;br /&gt;Organization : Deutsche Telekom AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Berlin, 16 -&lt;br /&gt;Latitude : 52°51'67" North&lt;br /&gt;Longitude : 13°40'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 171.6.83.121 [ 171.6.83.121 ]&lt;br /&gt;ISP : No Record Available&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.5.69 [ 24.64.5.69 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 63.179.244.236 [ 63.179.244.236 ]&lt;br /&gt;ISP : Sprint&lt;br /&gt;Organization : Sprint&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Sprint&lt;br /&gt;OrgID: : SPDN&lt;br /&gt;Address: : 12502 Sunrise Valley Dr&lt;br /&gt;City: : Reston&lt;br /&gt;StateProv: : VA&lt;br /&gt;PostalCode: : 20196&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 188.236.186.251 [ 188.236.186.251 ]&lt;br /&gt;OrgName: : RIPE Network Coordination Centre&lt;br /&gt;OrgID: : RIPE&lt;br /&gt;Address: : P.O. Box 10096&lt;br /&gt;City: : Amsterdam&lt;br /&gt;StateProv: :&lt;br /&gt;PostalCode: : 1001EB&lt;br /&gt;Country: : NL&lt;br /&gt;&lt;br /&gt;IP Address : 47.197.41.195 [ 47.197.41.195 ]&lt;br /&gt;ISP : Bell-Northern Research&lt;br /&gt;Organization : Nortel Networks&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Ottawa, ON k1y4h7&lt;br /&gt;Latitude : 45°41'67" North&lt;br /&gt;Longitude : 75°70'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.63.248 [ 24.64.63.248 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 132.46.24.227 [ 132.46.24.227 ]&lt;br /&gt;ISP : Columbus Air Force Base&lt;br /&gt;Organization : Columbus Air Force Base&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Columbus, MS 39710&lt;br /&gt;Latitude : 33°51'63" North&lt;br /&gt;Longitude : 88°46'01" West&lt;br /&gt;&lt;br /&gt;IP Address : 121.107.129.235 [ KD121107129235.ppp-bb.dion.ne.jp ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : DION (KDDI CORPORATION)&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : Tokyo, 40 -&lt;br /&gt;Latitude : 35°68'50" North&lt;br /&gt;Longitude : 139°75'14" East&lt;br /&gt;&lt;br /&gt;IP Address : 37.213.216.137 [ 37.213.216.137 ]&lt;br /&gt;OrgName: : Internet Assigned Numbers Authority&lt;br /&gt;OrgID: : IANA&lt;br /&gt;Address: : 4676 Admiralty Way, Suite 330&lt;br /&gt;City: : Marina del Rey&lt;br /&gt;StateProv: : CA&lt;br /&gt;PostalCode: : 90292-6695&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 15.4.16.227 [ 15.4.16.227 ]&lt;br /&gt;ISP : HEWLETT-PACKARD COMPANY&lt;br /&gt;Organization : Hewlett-Packard Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1027 ---------------&lt;br /&gt;IP Address : 24.64.5.69 [ 24.64.5.69 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;P Address : 24.64.63.248 [ 24.64.63.248 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1028 ----------------&lt;br /&gt;IP Address : 24.64.5.69 [ 24.64.5.69 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;P Address : 24.64.63.248 [ 24.64.63.248 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1433 ------------&lt;br /&gt;IP Address : 69.235.196.112 [ adsl-69-235-196-112.dsl.irvnca.pacbell.net ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : SBC Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Los Angeles, CA -&lt;br /&gt;Latitude : 34°04'16" North&lt;br /&gt;Longitude : 118°29'88" West&lt;br /&gt;&lt;br /&gt;----Port 1434 ------------&lt;br /&gt;IP Address : 69.251.102.139 [ c-69-251-102-139.hsd1.md.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Washington, DC -&lt;br /&gt;Latitude : 38°90'97" North&lt;br /&gt;Longitude : 77°02'31" West&lt;br /&gt;&lt;br /&gt;IP Address : 219.147.233.30 [ 219.147.233.30 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET HEILONGJIANG PROVINCE NETWORK&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Zhongshan, 07 -&lt;br /&gt;Latitude : 25°53'61" North&lt;br /&gt;Longitude : 118°78'97" East&lt;br /&gt;&lt;br /&gt;IP Address : 148.221.46.92 [ dup-148-221-46-92.prodigy.net.mx ]&lt;br /&gt;ISP : Uninet S.A. de C.V.&lt;br /&gt;Organization : Uninet S.A. de C.V.&lt;br /&gt;Location : MX, Mexico&lt;br /&gt;City : Monterrey, 19 -&lt;br /&gt;Latitude : 25°66'67" North&lt;br /&gt;Longitude : 100°31'67" West&lt;br /&gt;&lt;br /&gt;----Port 2967 ------------&lt;br /&gt;IP Address : 58.38.3.178 [&lt;br /&gt;178.3.38.58.broad.xw.sh.dynamic.163data.com.cn ]&lt;br /&gt;ISP : CHINANET Shanghai province network&lt;br /&gt;Organization : ChinaNet Shanghai Province Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.200.229.199 [ cpe-69-200-229-199.nyc.res.rr.com ]&lt;br /&gt;ISP : Road Runner&lt;br /&gt;Organization : Road Runner&lt;br /&gt;Location : US, United States&lt;br /&gt;City : New York, NY -&lt;br /&gt;Latitude : 40°76'19" North&lt;br /&gt;Longitude : 73°97'63" West&lt;br /&gt;&lt;br /&gt;----Port 5168 ------------&lt;br /&gt;IP Address : 58.247.11.242 [ 58.247.11.242 ]&lt;br /&gt;ISP : CNC Group ShangHai province network&lt;br /&gt;Organization : CNC Group ShangHai province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;----Port 5900 ------------&lt;br /&gt;IP Address : 189.170.15.107 [ dsl-189-170-15-107.prod-infinitum.com.mx ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Uninet S.A. de C.V.&lt;br /&gt;Location : MX, Mexico&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 23°00'00" North&lt;br /&gt;Longitude : 102°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 124.226.234.15 [ 124.226.234.15 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;IP Address : 217.127.100.8 [ 8.Red-217-127-100.staticIP.rima-tde.net ]&lt;br /&gt;ISP : Telefonica de Espana&lt;br /&gt;Organization : Red de servicios IP&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Madrid, 29 -&lt;br /&gt;Latitude : 40°40'00" North&lt;br /&gt;Longitude : 3°68'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 80.59.142.164 [ 164.Red-80-59-142.staticIP.rima-tde.net ]&lt;br /&gt;ISP : Telefonica de Espana&lt;br /&gt;Organization : Telefonica de Espana&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Viladecáns, 56 -&lt;br /&gt;Latitude : 41°31'67" North&lt;br /&gt;Longitude : 2°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 123.8.228.123 [ 123.8.228.123 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : CNCGROUP Henan province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 211.174.179.32 [ 211.174.179.32 ]&lt;br /&gt;ISP : KRNIC&lt;br /&gt;Organization : ELIMNET-IDC&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seoul, 11 -&lt;br /&gt;Latitude : 37°56'64" North&lt;br /&gt;Longitude : 126°99'97" East&lt;br /&gt;&lt;br /&gt;IP Address : 124.224.128.140 [ 124.224.128.140 ]&lt;br /&gt;ISP : CHINANET ningxia province network&lt;br /&gt;Organization : CHINANET ningxia province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 7212 ------------&lt;br /&gt;IP Address : 218.234.38.69 [ 218.234.38.69 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Eunsan&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity On Port 80 -------&lt;br /&gt;IP Address : 209.128.104.84 [ 209-128-104-084.bayarea.net ]&lt;br /&gt;ISP : Bay Area Internet Solutions&lt;br /&gt;Organization : Go Click Media&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Los Altos, CA 94024&lt;br /&gt;Latitude : 37°34'95" North&lt;br /&gt;Longitude : 122°11'63" West&lt;br /&gt;&lt;br /&gt;IP Address : 159.148.97.48 [ 159.148.97.48 ]&lt;br /&gt;ISP : LATNET&lt;br /&gt;Organization : LATNET ISP&lt;br /&gt;Location : LV, Latvia&lt;br /&gt;City : Riga, 25 -&lt;br /&gt;Latitude : 56°95'00" North&lt;br /&gt;Longitude : 24°10'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 68.187.226.170 [ 68-187-226-170.dhcp.oxfr.ma.charter.com ]&lt;br /&gt;ISP : CHARTER COMMUNICATIONS&lt;br /&gt;Organization : CHARTER COMMUNICATIONS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Dudley, MA 01571&lt;br /&gt;Latitude : 42°05'94" North&lt;br /&gt;Longitude : 71°93'56" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-8312043343595040855?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/8312043343595040855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=8312043343595040855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/8312043343595040855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/8312043343595040855'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-25-2007.html' title='Cyber Center Report - October 25, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-579611522112467176</id><published>2007-10-28T21:55:00.000-04:00</published><updated>2007-10-28T23:49:12.645-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 24, 2007</title><content type='html'>BLSS Cyber Center Report - 24 October 2007&lt;br /&gt;------------------------------------------&lt;br /&gt;&lt;br /&gt;Last night's probes/attacks were just as severe as the reports on the 22nd and 23rd of October. All previously reported probes/attacks from China and Korea continue (and increase in frequency, including all previously report ports, 7212, 1026, etc.). We have detected two new (active) ports, which are 5168 and 6588.&lt;br /&gt;&lt;br /&gt;New Activity on Port 1026; U.S. (United States Postal Service), Merck and Co., Mexico, Netherlands and China (two new sites).&lt;br /&gt;&lt;br /&gt;Port 22; U.S. (one new site), Port 1080; China (new site). Port 1433; South Africa, U.S. (Interesting observation; two U.S. termite control companies are now (both) broadcasting on port 1433). Port 1434; Oman (new site), China (new site). Port 2967; U.S. (2 new sites), China (new site), One IP address that cannot be identified (69.245.257.182). Port 5168; China (2 new sites). Port 5900; China (2 new sites), Spain, U.S. (2 new sites). Port 6588; Korea (new site). Reported probes from users of Comcast Cable ISP; China, Canada and Israel are probing Comcast Cable ISP. Another interesting observation, is that many of the U.S. IPs now broadcasting are from within Comcast Cable. BLSS Honey Pot Activity; Users "surfed" the honey pot. No honey pot attacks last night.&lt;br /&gt;&lt;br /&gt;The BLSS honey pot was surfed in Nashville, TN, and from two sites within the United Kingdom (UK).&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026 -------------&lt;br /&gt;IP Address : 56.241.240.196 [ 56.241.240.196 ]&lt;br /&gt;ISP : United States Postal Service.&lt;br /&gt;Organization : United States Postal Service.&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Raleigh, NC 27668&lt;br /&gt;Latitude : 35°79'77" North&lt;br /&gt;Longitude : 78°62'53" West&lt;br /&gt;&lt;br /&gt;IP Address : 186.242.205.146&lt;br /&gt;OrgName: : Latin American and Caribbean IP address Regional Registry&lt;br /&gt;OrgID: : LACNIC&lt;br /&gt;Address: : Rambla Republica de Mexico 6125&lt;br /&gt;City: : Montevideo&lt;br /&gt;StateProv: :&lt;br /&gt;PostalCode: : 11400&lt;br /&gt;Country: : UY&lt;br /&gt;&lt;br /&gt;IP Address : 95.229.160.163&lt;br /&gt;OrgName: : RIPE Network Coordination Centre&lt;br /&gt;OrgID: : RIPE&lt;br /&gt;Address: : P.O. Box 10096&lt;br /&gt;City: : Amsterdam&lt;br /&gt;StateProv: :&lt;br /&gt;PostalCode: : 1001EB&lt;br /&gt;Country: : NL&lt;br /&gt;&lt;br /&gt;IP Address : 54.108.221.74 [ 54.108.221.74 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Merck and Co., Inc.&lt;br /&gt;OrgID: : MERCKA&lt;br /&gt;Address: : 126 East Lincoln Avenue&lt;br /&gt;City: : Rahway&lt;br /&gt;StateProv: : NJ&lt;br /&gt;PostalCode: : 07095&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 59.56.27.170 [&lt;br /&gt;170.27.56.59.broad.fz.fj.dynamic.163data.com.cn ]&lt;br /&gt;ISP : chinanet fujian province network&lt;br /&gt;Organization : chinanet fujian province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 58.221.33.13 [ 58.221.33.13 ]&lt;br /&gt;ISP : CHINANET jiangsu province network&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----Port 22 ---------------&lt;br /&gt;IP Address : 72.249.66.73 [ 72.249.66.73 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Colo4Dallas LP&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Dallas, TX 75247&lt;br /&gt;Latitude : 32°81'48" North&lt;br /&gt;Longitude : 96°87'06" West&lt;br /&gt;&lt;br /&gt;----Port 1080 -------------&lt;br /&gt;IP Address : 219.153.5.169 [&lt;br /&gt;169.5.153.219.broad.cq.cq.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Data Communication Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;----Port 1433 -------------&lt;br /&gt;IP Address : 216.135.181.59 [ user-vc8fd9r.biz.mindspring.com ]&lt;br /&gt;ISP : EarthLink&lt;br /&gt;Organization : Higgins Termite Inc&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Rancho Cucamonga, CA -&lt;br /&gt;Latitude : 34°14'60" North&lt;br /&gt;Longitude : 117°57'99" West&lt;br /&gt;&lt;br /&gt;IP Address : 196.30.221.68 [ 196.30.221.68 ]&lt;br /&gt;ISP : Verizon South Africa&lt;br /&gt;Organization : Verizon South Africa&lt;br /&gt;Location : ZA, South Africa&lt;br /&gt;City : Cape Town, 11 -&lt;br /&gt;Latitude : 33°91'67" South&lt;br /&gt;Longitude : 18°41'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 63.205.221.242 [ 63.205.221.242 ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : Zap Termite &amp;amp; Pest Control&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Stockton, CA -&lt;br /&gt;Latitude : 37°98'61" North&lt;br /&gt;Longitude : 121°29'98" West&lt;br /&gt;&lt;br /&gt;----Port 1434 --------------&lt;br /&gt;IP Address : 82.178.22.22 [ 82.178.22.22 ]&lt;br /&gt;ISP : Oman&lt;br /&gt;Organization : Muscat Ltd&lt;br /&gt;Location : OM, Oman&lt;br /&gt;City : Muscat, 06 -&lt;br /&gt;Latitude : 23°61'33" North&lt;br /&gt;Longitude : 58°59'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 220.191.252.62 [ 220.191.252.62 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Lishui Electronic Government Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Lishui, 02 -&lt;br /&gt;Latitude : 28°11'08" North&lt;br /&gt;Longitude : 119°56'39" East&lt;br /&gt;&lt;br /&gt;----Port 2967 --------------&lt;br /&gt;IP Address : 69.136.183.203 [ c-69-136-183-203.hsd1.in.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Eatontown, NJ -&lt;br /&gt;Latitude : 40°30'39" North&lt;br /&gt;Longitude : 74°07'03" West&lt;br /&gt;&lt;br /&gt;IP Address : 69.245.257.182&lt;br /&gt;: No Records Available&lt;br /&gt;&lt;br /&gt;IP Address : 58.241.178.210 [ 58.241.178.210 ]&lt;br /&gt;ISP : CNC Group Jiangsu province network&lt;br /&gt;Organization : PEIXIANYINGYE-COM,XUZHOU,JIANGSU Province&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Xuzhou, 04 -&lt;br /&gt;Latitude : 34°26'69" North&lt;br /&gt;Longitude : 117°19'16" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.125.171.226 [ ool-457dabe2.dyn.optonline.net ]&lt;br /&gt;ISP : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Hicksville, NY 11801&lt;br /&gt;Latitude : 40°76'70" North&lt;br /&gt;Longitude : 73°52'54" West&lt;br /&gt;&lt;br /&gt;----Port 5168 --------------&lt;br /&gt;IP Address : 61.130.134.66 [&lt;br /&gt;66.134.130.61.broad.hz.zj.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-ZJ Hangzhou node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hangzhou, 02 -&lt;br /&gt;Latitude : 30°25'53" North&lt;br /&gt;Longitude : 120°16'89" East&lt;br /&gt;&lt;br /&gt;IP Address : 61.130.134.66 [&lt;br /&gt;66.134.130.61.broad.hz.zj.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-ZJ Hangzhou node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hangzhou, 02 -&lt;br /&gt;Latitude : 30°25'53" North&lt;br /&gt;Longitude : 120°16'89" East&lt;br /&gt;&lt;br /&gt;----Port 5900 --------------&lt;br /&gt;IP Address : 222.216.28.178 [ 222.216.28.178 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.248.159.104 [ c-69-248-159-104.hsd1.nj.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cherry Hill, NJ -&lt;br /&gt;Latitude : 39°90'84" North&lt;br /&gt;Longitude : 74°99'83" West&lt;br /&gt;&lt;br /&gt;IP Address : 70.8.51.83 [ h46083353.area4.spcsdns.net ]&lt;br /&gt;ISP : Sprint PCS&lt;br /&gt;Organization : Sprint PCS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : West Bend, WI -&lt;br /&gt;Latitude : 43°42'97" North&lt;br /&gt;Longitude : 88°18'31" West&lt;br /&gt;&lt;br /&gt;IP Address : 124.224.131.132 [ 124.224.131.132 ]&lt;br /&gt;ISP : CHINANET ningxia province network&lt;br /&gt;Organization : CHINANET ningxia province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 80.24.234.121 [ 121.Red-80-24-234.staticIP.rima-tde.net ]&lt;br /&gt;ISP : Telefonica Data Espana&lt;br /&gt;Organization : Telefonica de Espana&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Madrid, 29 -&lt;br /&gt;Latitude : 40°40'00" North&lt;br /&gt;Longitude : 3°68'33" West&lt;br /&gt;&lt;br /&gt;----Port 6588 --------------&lt;br /&gt;IP Address : 218.234.41.8 [ 218.234.41.8 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : SEOULMEDIA&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----Reported Probes Within Comcast Cable-------&lt;br /&gt;IP Address : 24.64.106.160 [ S01060014bfe0176a.cg.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB -&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 62.90.138.197 [ 62-90-138-197.interhost.co.il ]&lt;br /&gt;ISP : Barak I.T.C&lt;br /&gt;Organization : Barak I.T.C.&lt;br /&gt;Location : IL, Israel&lt;br /&gt;City : Tel Aviv-Yafo, 05 -&lt;br /&gt;Latitude : 32°06'78" North&lt;br /&gt;Longitude : 34°76'47" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.27.148.78 [ 218.27.148.78 ]&lt;br /&gt;ISP : CNCGROUP Jilin province network&lt;br /&gt;Organization : CNCGROUP Jilin province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Changchun, 05 -&lt;br /&gt;Latitude : 43°88'00" North&lt;br /&gt;Longitude : 125°32'28" East&lt;br /&gt;&lt;br /&gt;----Honey Pot Activity -------------&lt;br /&gt;IP Address : 71.228.243.95 [ c-71-228-243-95.hsd1.tn.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Nashville, TN -&lt;br /&gt;Latitude : 36°14'58" North&lt;br /&gt;Longitude : 86°78'44" West&lt;br /&gt;&lt;br /&gt;IP Address : 81.100.113.6 [&lt;br /&gt;spc1-pool7-0-0-cust261.cosh.broadband.ntl.com ]&lt;br /&gt;ISP : NTL Internet&lt;br /&gt;Organization : NTL Internet&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : Borehamwood, K8 -&lt;br /&gt;Latitude : 51°65'00" North&lt;br /&gt;Longitude : 0°26'67" West&lt;br /&gt;&lt;br /&gt;IP Address : 88.110.111.176 [ 88-110-111-176.dynamic.dsl.as9105.com ]&lt;br /&gt;ISP : Tiscali UK Limited&lt;br /&gt;Organization : Tiscali UK Ltd&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-579611522112467176?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/579611522112467176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=579611522112467176' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/579611522112467176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/579611522112467176'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-24-2007.html' title='Cyber Center Report - October 24, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-1566652273647485439</id><published>2007-10-28T21:54:00.000-04:00</published><updated>2007-10-29T08:13:45.019-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 23, 2007</title><content type='html'>Black Lab Security Cyber Center Report&lt;br /&gt;Tuesday, October 23, 2007 (5:20 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecuirty.com/"&gt;http://www.blacklabsecuirty.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Summary of Overnight Internet Activity&lt;br /&gt;---------------------------------------&lt;br /&gt;&lt;br /&gt;Last night's probes/attacks were just as severe as yesterday's report for 22 October 2007. All IP addresses reported from China and Korea are continuous probes/attacks against the U.S. New probes/attacks for Port 1026; Netherlands, Australia (new site), U.S. (two new sites, one is unidentifiable (BellSouth ISP) and the second is from within Prudential Securities), Canada (new site), China (three new sites). Port 1027; Canada (new site), China (three new sites). Port 1028; Canada (new site). Port 21; France (new site). Port 22; China (new site), U.S. (new site). Port 1080; Korea (new site). Port 1433; Brazil (new site), Germany (new site), Belgrade (new site). Port 1434: China (four new sites - an interesting observation is that one Chinese Police Bureau is probing/attacking the U.S.) Port 2967; China (new site), U.S. (new site). Port 2968; U.S. (new site).&lt;br /&gt;Port 4899; Bangkok (new site), China (new site), Korea (new site). Port 445; U.S. (new site). Port 5900; India (new site), Columbia (new site), Hungary (new site) U.S. (three new sites). Honey Pot activity; One U.S. site located in Fort Myers, Florida, manually "surfed" the honey pot, then ran a series of programs attacking our honey pot for over two hours. The Fort Myers, FL web site attacked our honey pot on ports 21, 1434, 1080, 1024, 1028, 22 and 25. The Fort Myers, FL attack against our honey pot was completely unsuccessful. One other site located in Canada, manually surfed the honey pot, but did NOT attack the honey pot.&lt;br /&gt;&lt;br /&gt;Summary: The overall world-wide probes/attacks appear to be escalating at an alarming rate.&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026 ---------&lt;br /&gt;IP Address : 134.143.150.233 [ 134.143.150.233 ]&lt;br /&gt;ISP : Shell Information Technology International&lt;br /&gt;Organization : SHELL INFORMATION TECHNOLOGY INTERNATIONAL&lt;br /&gt;Location : NL, Netherlands&lt;br /&gt;City : Leidschendam, 11 -&lt;br /&gt;Latitude : 52°08'33" North&lt;br /&gt;Longitude : 4°40'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 120.7.19.217 [ 120.7.19.217 ]&lt;br /&gt;OrgName: : Asia Pacific Network Information Centre&lt;br /&gt;OrgID: : APNIC&lt;br /&gt;Address: : PO Box 2131&lt;br /&gt;City: : Milton&lt;br /&gt;StateProv: : QLD&lt;br /&gt;PostalCode: : 4064&lt;br /&gt;Country: : AU&lt;br /&gt;&lt;br /&gt;IP Address : 74.185.81.158 [ adsl-074-185-081-158.sip.bhm.bellsouth.net ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : BellSouth.net&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.62.245 [ S01060015e968d547.cn.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 221.209.110.50 [ 221.209.110.50 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 48.48.158.238 [ 48.48.158.238 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName: : Prudential Securities Inc.&lt;br /&gt;OrgID: : PRUDEN-1&lt;br /&gt;Address: : 1 New York Plaza&lt;br /&gt;City: : New York&lt;br /&gt;StateProv: : NY&lt;br /&gt;PostalCode: : 10004&lt;br /&gt;Country: : US&lt;br /&gt;&lt;br /&gt;IP Address : 218.10.137.142 [ 218.10.137.142 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.209.110.20 [ 221.209.110.20 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;----Port 1027 --------&lt;br /&gt;IP Address : 24.64.62.245 [ S01060015e968d547.cn.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 221.209.110.50 [ 221.209.110.50 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.10.137.142 [ 218.10.137.142 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.209.110.20 [ 221.209.110.20 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;----Port 1028 ---------&lt;br /&gt;IP Address : 24.64.62.245 [ S01060015e968d547.cn.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 21 ----------&lt;br /&gt;IP Address : 88.168.212.117 [ pon89-1-88-168-212-117.fbx.proxad.net ]&lt;br /&gt;ISP : Proxad&lt;br /&gt;Organization : Proxad / Free SAS&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Paris, A8 -&lt;br /&gt;Latitude : 48°86'67" North&lt;br /&gt;Longitude : 2°33'33" East&lt;br /&gt;&lt;br /&gt;----Port 22 ----------&lt;br /&gt;IP Address : 202.75.218.145 [ 202.75.218.145 ]&lt;br /&gt;ISP : Hangzhou Silk Road Information Technologies Co.,Lt&lt;br /&gt;Organization : Hangzhou Silk Road Information Technologies Co.,Lt&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hangzhou, 02 -&lt;br /&gt;Latitude : 30°25'53" North&lt;br /&gt;Longitude : 120°16'89" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.60.115.111 [ 111-115-60-69.serverpronto.com ]&lt;br /&gt;ISP : Infolink Information Services&lt;br /&gt;Organization : Serverpronto&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fort Lauderdale, FL -&lt;br /&gt;Latitude : 26°12'75" North&lt;br /&gt;Longitude : 80°23'31" West&lt;br /&gt;&lt;br /&gt;----Port 1080 ----------&lt;br /&gt;IP Address : 222.239.255.43 [ 222.239.255.43 ]&lt;br /&gt;ISP : Hanaro Telecom, Inc.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seoul, 11 -&lt;br /&gt;Latitude : 37°56'64" North&lt;br /&gt;Longitude : 126°99'97" East&lt;br /&gt;&lt;br /&gt;----Port 1433 ----------&lt;br /&gt;IP Address : 201.88.53.138 [&lt;br /&gt;201-10-128-138.gnace304.ipd.brasiltelecom.net.br ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Location : BR, Brazil&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 10°00'00" South&lt;br /&gt;Longitude : 55°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 87.106.66.212 [ s15242027.onlinehome-server.info ]&lt;br /&gt;ISP : Schlund+Partner AG&lt;br /&gt;Organization : Schlund + Partner AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Karlsruhe, 01 -&lt;br /&gt;Latitude : 49°00'47" North&lt;br /&gt;Longitude : 8°38'58" East&lt;br /&gt;&lt;br /&gt;IP Address : 212.200.228.229 [ sipdc2.telekom.yu ]&lt;br /&gt;ISP : TELEKOM SRBIJA&lt;br /&gt;Organization : TELEKOM SRBIJA&lt;br /&gt;Location : CS, Serbia and Montenegro&lt;br /&gt;City : Belgrade, 02 -&lt;br /&gt;Latitude : 44°81'86" North&lt;br /&gt;Longitude : 20°46'81" East&lt;br /&gt;&lt;br /&gt;----Port 1434 ----------&lt;br /&gt;IP Address : 61.189.154.33 [ 61.189.154.33 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET Guizhou province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.106.91.25 [ 218.106.91.25 ]&lt;br /&gt;ISP : CNCGROUP IP network&lt;br /&gt;Organization : hefei city&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hefei, 01 -&lt;br /&gt;Latitude : 31°86'39" North&lt;br /&gt;Longitude : 117°28'08" East&lt;br /&gt;&lt;br /&gt;IP Address : 220.191.233.132 [ 220.191.233.132 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Taizhou Electronic Government Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Taizhou, 04 -&lt;br /&gt;Latitude : 32°49'33" North&lt;br /&gt;Longitude : 119°90'81" East&lt;br /&gt;&lt;br /&gt;IP Address : 220.179.244.138 [ 220.179.244.138 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET Anhui province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hefei, 01 -&lt;br /&gt;Latitude : 31°86'39" North&lt;br /&gt;Longitude : 117°28'08" East&lt;br /&gt;&lt;br /&gt;IP Address : 61.175.243.182 [ 61.175.243.182 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Jinyun Police Bureau (Fangkong And Fangbao)&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Jinyun, 18 -&lt;br /&gt;Latitude : 27°44'67" North&lt;br /&gt;Longitude : 106°30'33" East&lt;br /&gt;&lt;br /&gt;----Port 2967 ----------&lt;br /&gt;IP Address : 58.241.178.213 [ 58.241.178.213 ]&lt;br /&gt;ISP : CNC Group Jiangsu province network&lt;br /&gt;Organization : PEIXIANYINGYE-COM,XUZHOU,JIANGSU Province&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Xuzhou, 04 -&lt;br /&gt;Latitude : 34°26'69" North&lt;br /&gt;Longitude : 117°19'16" East&lt;br /&gt;&lt;br /&gt;----Port 2968 ----------&lt;br /&gt;IP Address : 69.14.134.88 [ d14-69-88-134.try.wideopenwest.com ]&lt;br /&gt;ISP : WIDEOPENWEST&lt;br /&gt;Organization : WideOpenWest&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Detroit, MI -&lt;br /&gt;Latitude : 42°36'62" North&lt;br /&gt;Longitude : 83°10'15" West&lt;br /&gt;&lt;br /&gt;----Port 4899 ----------&lt;br /&gt;IP Address : 58.97.5.64 [ 58-97-5-64.static.asianet.co.th ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Fix ip for coporate customer&lt;br /&gt;Location : TH, Thailand&lt;br /&gt;City : Bangkok, 40 -&lt;br /&gt;Latitude : 13°75'00" North&lt;br /&gt;Longitude : 100°51'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 222.217.221.214 [ 222.217.221.214 ]&lt;br /&gt;ISP : CHINANET Guangxi province network&lt;br /&gt;Organization : CHINANET Guangxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Nanning, 16 -&lt;br /&gt;Latitude : 22°81'67" North&lt;br /&gt;Longitude : 108°31'66" East&lt;br /&gt;&lt;br /&gt;IP Address : 122.38.90.165 [ 122.38.90.165 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : POWERCOMM&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Port 445 -----------&lt;br /&gt;IP Address : 69.128.208.251 [ lncswibas01-pool0-a251.lncswi.tds.net ]&lt;br /&gt;ISP : TDS TELECOM&lt;br /&gt;Organization : TDS TELECOM&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Madison, WI -&lt;br /&gt;Latitude : 43°07'14" North&lt;br /&gt;Longitude : 89°39'32" West&lt;br /&gt;&lt;br /&gt;----Port 5900 ----------&lt;br /&gt;IP Address : 124.124.128.2 [ 124.124.128.2 ]&lt;br /&gt;ISP : Reliance Infocomm Limited,&lt;br /&gt;Organization : Reliance Infocomm Limited&lt;br /&gt;Location : IN, India&lt;br /&gt;City : Bombay, 16 -&lt;br /&gt;Latitude : 18°97'50" North&lt;br /&gt;Longitude : 72°82'58" East&lt;br /&gt;&lt;br /&gt;IP Address : 201.221.176.50 [ 201.221.176.50 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Comercial Dinamica&lt;br /&gt;Location : CO, Colombia&lt;br /&gt;City : Barranquilla, 04 -&lt;br /&gt;Latitude : 10°96'39" North&lt;br /&gt;Longitude : 74°79'64" West&lt;br /&gt;&lt;br /&gt;IP Address : 213.222.152.109 [ 213.222.152.109 ]&lt;br /&gt;ISP : UPC Magyarorszag Kft.&lt;br /&gt;Organization : UPC Magyarorszag Kft.&lt;br /&gt;Location : HU, Hungary&lt;br /&gt;City : Budapest, 05 -&lt;br /&gt;Latitude : 47°50'00" North&lt;br /&gt;Longitude : 19°08'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 216.196.87.181 [ 216.196.87.181 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : POLAR COMMUNICATIONS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Park River, ND 58270&lt;br /&gt;Latitude : 48°38'36" North&lt;br /&gt;Longitude : 97°78'56" West&lt;br /&gt;&lt;br /&gt;IP Address : 205.153.244.5 [ gw.tri.net ]&lt;br /&gt;ISP : Tri-Rivers Internet&lt;br /&gt;Organization : Tri-Rivers Internet&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Salina, KS 67401&lt;br /&gt;Latitude : 38°85'22" North&lt;br /&gt;Longitude : 97°61'42" West&lt;br /&gt;&lt;br /&gt;IP Address : 69.119.237.210 [ ool-4577edd2.dyn.optonline.net ]&lt;br /&gt;ISP : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Yonkers, NY -&lt;br /&gt;Latitude : 40°94'35" North&lt;br /&gt;Longitude : 73°87'13" West&lt;br /&gt;&lt;br /&gt;IP Address : 72.54.39.150 [ 72.54.39.150 ]&lt;br /&gt;ISP : CBEYOND COMMUNICATIONS&lt;br /&gt;Organization : CBEYOND COMMUNICATIONS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Atlanta, GA 30339&lt;br /&gt;Latitude : 33°87'10" North&lt;br /&gt;Longitude : 84°46'35" West&lt;br /&gt;&lt;br /&gt;----Port 7212 -----------&lt;br /&gt;IP Address : 218.234.38.69 [ 218.234.38.69 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Eunsan&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.11.6.197 [ 221.11.6.197 ]&lt;br /&gt;ISP : CNC Group Shannxi province network&lt;br /&gt;Organization : CNC Group Shannxi province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Taiyüan, 24 -&lt;br /&gt;Latitude : 37°72'69" North&lt;br /&gt;Longitude : 112°47'08" East&lt;br /&gt;&lt;br /&gt;---- Honey Pot Attacks -------&lt;br /&gt;IP Address : 71.3.26.23 [ fl-71-3-26-23.dhcp.embarqhsd.net ]&lt;br /&gt;ISP : Sprint DSL&lt;br /&gt;Organization : Embarq Corporation&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fort Myers, FL -&lt;br /&gt;Latitude : 26°57'37" North&lt;br /&gt;Longitude : 81°82'69" West&lt;br /&gt;&lt;br /&gt;IP Address : 69.157.7.52 [ bas2-hamilton14-1167918900.dsl.bell.ca ]&lt;br /&gt;ISP : Bell Canada&lt;br /&gt;Organization : Sympatico&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Hamilton, ON -&lt;br /&gt;Latitude : 43°25'00" North&lt;br /&gt;Longitude : 79°83'33" West&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-1566652273647485439?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/1566652273647485439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=1566652273647485439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/1566652273647485439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/1566652273647485439'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-23-2007.html' title='Cyber Center Report - October 23, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-7083566543304381674</id><published>2007-10-28T21:53:00.000-04:00</published><updated>2007-10-29T08:14:49.227-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 22, 2007</title><content type='html'>Black Lab Security Cyber Center Report&lt;br /&gt;Monday, October 22, 2007 (10:12 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecuirty.com/"&gt;http://www.blacklabsecuirty.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Summary of Overnight Internet Activity&lt;br /&gt;--------------------------------------&lt;br /&gt;&lt;br /&gt;BLSS has detected and observed the worst night of probes/attacks since we started reporting internet activity. Last night was a new record (high) for new sites and new ports being probed/attacked. More sites have been established in China and Korea, continuously probing/attacking the U.S. Two U.S. Department Of Defense (DoD) computers were successfully breached, now broadcasting on port 1026. The DoD computers are; 1) IP address 11.104.193.153, located (approximately) in Colorado, which is part of the DoD Network Centric Operations, 2) IP Address 155.147.1.82, Director Of Logistics, located at Fort Rucker, AL. The California Institute Of Health is now broadcasting on port 1433.&lt;br /&gt;&lt;br /&gt;The following new countries are probing/attacking on port 1026; China (new sites), Tunisia, Canada (new site), U.S. (new site) and Italy. Port 1027; China (new site), Canada (new site). Port 1028; Canada (new site). Port 21; UK (London). Port 22; UK (London), Port 25; Japan (Tokyo). Port 445; China (new site), U.S., (new site). Port 1433: U.S. (new site). Port 1434; India, Romania, China (2 new sites), Taiwan. Port 1080; China (new site), Korea (new site). Port 2967; China (new site). Port 4899; Turkey, China (new site). Port 5900; Italy, China (new site). Port 7212; Korea (new site).&lt;br /&gt;Port 8180; Slovakia. The BLSS Honey Pot; Web surfed (only) by Australia and U.S. - no attempted attacks by web surfers on the BLSS honey pot.&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026&lt;br /&gt;IP Address : 218.10.137.142 [ 218.10.137.142 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Harbin, 08 -&lt;br /&gt;Latitude : 45°75'00" North&lt;br /&gt;Longitude : 126°65'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 221.209.110.20 [ 221.209.110.20 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 155.147.1.82 [ 155.147.1.82 ]&lt;br /&gt;ISP : DIRECTORATE OF LOGISTICS&lt;br /&gt;Organization : DIRECTORATE OF LOGISTICS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fort Rucker, AL 36362&lt;br /&gt;Latitude : 31°34'97" North&lt;br /&gt;Longitude : 85°68'46" West&lt;br /&gt;&lt;br /&gt;IP Address : 41.225.91.172 [ 41.225.91.172 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Agence Tunisienne Internet - ATI&lt;br /&gt;Location : TN, Tunisia&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 34°00'00" North&lt;br /&gt;Longitude : 9°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.255.53 [ 24.64.255.53 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 8.63.130.197 [ 8.63.130.197 ]&lt;br /&gt;ISP : Level 3 Communications&lt;br /&gt;Organization : Level 3 Communications&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 11.104.193.153 [ 11.104.193.153 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;OrgName : DoD Network Information Center&lt;br /&gt;OrgID : DNIC&lt;br /&gt;Address : 3990 E. Broad Street&lt;br /&gt;City : Columbus&lt;br /&gt;StateProv : OH&lt;br /&gt;PostalCode : 43218&lt;br /&gt;Country : US&lt;br /&gt;&lt;br /&gt;IP Address : 77.93.236.103 [ 77-93-236-103.dcpool.ip.kpnqwest.it ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : KPNQwest Italia S.p.a.&lt;br /&gt;Location : IT, Italy&lt;br /&gt;City : Milan, 09 -&lt;br /&gt;Latitude : 45°46'67" North&lt;br /&gt;Longitude : 9°20'00" East&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----Port 1027&lt;br /&gt;IP Address : 221.209.110.20 [ 221.209.110.20 ]&lt;br /&gt;ISP : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Mudanjiang, 08 -&lt;br /&gt;Latitude : 44°58'33" North&lt;br /&gt;Longitude : 129°60'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.64.255.53 [ 24.64.255.53 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;----Port 1028&lt;br /&gt;IP Address : 24.64.255.53 [ 24.64.255.53 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;-----Port 21&lt;br /&gt;IP Address : 78.86.141.137 [ 78-86-141-137.zone2.bethere.co.uk ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Be Un Limited&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : London, H9 -&lt;br /&gt;Latitude : 51°50'00" North&lt;br /&gt;Longitude : 0°11'67" West&lt;br /&gt;&lt;br /&gt;----Port 22&lt;br /&gt;IP Address : 78.86.141.137 [ 78-86-141-137.zone2.bethere.co.uk ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Be Un Limited&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : London, H9 -&lt;br /&gt;Latitude : 51°50'00" North&lt;br /&gt;Longitude : 0°11'67" West&lt;br /&gt;&lt;br /&gt;----Port 25&lt;br /&gt;IP Address : 219.166.34.82 [ piano.tokyo-club.com ]&lt;br /&gt;ISP : OCN Provided By NTT-Communications which is ISP&lt;br /&gt;Organization : Tokyo Printing inc.&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : Tokyo, 40 -&lt;br /&gt;Latitude : 35°68'50" North&lt;br /&gt;Longitude : 139°75'14" East&lt;br /&gt;&lt;br /&gt;----Port 445&lt;br /&gt;IP Address : 124.114.116.18 [&lt;br /&gt;18.116.114.124.broad.xa.sn.dynamic.163data.com.cn ]&lt;br /&gt;ISP : CHINANET Shanxi(SN) province network&lt;br /&gt;Organization : CHINANET Shanxi(SN) province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.128.208.251 [ lncswibas01-pool0-a251.lncswi.tds.net ]&lt;br /&gt;ISP : TDS TELECOM&lt;br /&gt;Organization : TDS TELECOM&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Madison, WI -&lt;br /&gt;Latitude : 43°07'14" North&lt;br /&gt;Longitude : 89°39'32" West&lt;br /&gt;&lt;br /&gt;----Port 1433&lt;br /&gt;IP Address : 75.8.241.35 [ 75.8.241.35 ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : Ca Inst Of Hlth Soc&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 69.121.3.83 [ ool-45790353.dyn.optonline.net ]&lt;br /&gt;ISP : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Mamaroneck, NY 10543&lt;br /&gt;Latitude : 40°95'21" North&lt;br /&gt;Longitude : 73°73'82" West&lt;br /&gt;&lt;br /&gt;----Port 1434&lt;br /&gt;IP Address : 203.94.243.191 [ 203.94.243.191 ]&lt;br /&gt;ISP : Mahanagar Telephone Nigam Ltd., ISP Division, New&lt;br /&gt;Organization : Mahanagar Telephone Nigam Ltd., ISP Division, New&lt;br /&gt;Location : IN, India&lt;br /&gt;City : New Delhi, 07 -&lt;br /&gt;Latitude : 28°60'00" North&lt;br /&gt;Longitude : 77°20'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 82.78.22.22 [ 82-78-22-22.rdsnet.ro ]&lt;br /&gt;ISP : RCS &amp;amp; RDS SA&lt;br /&gt;Organization : SC TELCOR COMMUNICATIONS SRL&lt;br /&gt;Location : RO, Romania&lt;br /&gt;City : Bucharest, 10 -&lt;br /&gt;Latitude : 44°43'33" North&lt;br /&gt;Longitude : 26°10'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 219.147.233.40 [ 219.147.233.40 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET HEILONGJIANG PROVINCE NETWORK&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Zhongshan, 07 -&lt;br /&gt;Latitude : 25°53'61" North&lt;br /&gt;Longitude : 118°78'97" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.75.199.50 [ 218.75.199.50 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-HN Zhuzhou node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hunan, 07 -&lt;br /&gt;Latitude : 25°97'14" North&lt;br /&gt;Longitude : 119°64'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.165.8.32 [ 218-165-8-32.dynamic.hinet.net ]&lt;br /&gt;ISP : CHTD, Chunghwa Telecom Co.,Ltd.&lt;br /&gt;Organization : Chunghwa Telecom Data communication Business Group&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;----Port 1080&lt;br /&gt;IP Address : 222.169.226.169 [ 222.169.226.169 ]&lt;br /&gt;ISP : CHINANET Jilin province network&lt;br /&gt;Organization : CHINANET JILIN PROVINCE NETWORK&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Changchun, 05 -&lt;br /&gt;Latitude : 43°88'00" North&lt;br /&gt;Longitude : 125°32'28" East&lt;br /&gt;&lt;br /&gt;IP Address : 222.239.255.43 [ 222.239.255.43 ]&lt;br /&gt;ISP : Hanaro Telecom, Inc.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seoul, 11 -&lt;br /&gt;Latitude : 37°56'64" North&lt;br /&gt;Longitude : 126°99'97" East&lt;br /&gt;&lt;br /&gt;----Port 2967&lt;br /&gt;IP Address : 61.130.50.150 [ 61.130.50.150 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-ZJ Quzhou node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Quzhou, 02 -&lt;br /&gt;Latitude : 28°95'93" North&lt;br /&gt;Longitude : 118°86'86" East&lt;br /&gt;&lt;br /&gt;---Port 4899&lt;br /&gt;IP Address : 221.158.228.40 [ 221.158.228.40 ]&lt;br /&gt;ISP : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 88.248.17.231 [ dsl88-248-4583.ttnet.net.tr ]&lt;br /&gt;ISP : Turk Telekom&lt;br /&gt;Organization : Turk Telekom&lt;br /&gt;Location : TR, Turkey&lt;br /&gt;City : Ankara, 68 -&lt;br /&gt;Latitude : 39°92'72" North&lt;br /&gt;Longitude : 32°86'44" East&lt;br /&gt;&lt;br /&gt;----Port 5900&lt;br /&gt;IP Address : 82.91.191.37 [&lt;br /&gt;host37-191-static.91-82-b.business.telecomitalia.it ]&lt;br /&gt;ISP : Telecom Italia Wireline Services&lt;br /&gt;Organization : Telecom Italia Wireline Services&lt;br /&gt;Location : IT, Italy&lt;br /&gt;City : Chieti, 01 -&lt;br /&gt;Latitude : 42°35'00" North&lt;br /&gt;Longitude : 14°16'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 124.114.116.18 [&lt;br /&gt;18.116.114.124.broad.xa.sn.dynamic.163data.com.cn ]&lt;br /&gt;ISP : CHINANET Shanxi(SN) province network&lt;br /&gt;Organization : CHINANET Shanxi(SN) province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----8180&lt;br /&gt;IP Address : 85.248.121.12 [ 85.248.121.12 ]&lt;br /&gt;ISP : GTS INEC a.s.&lt;br /&gt;Organization : LightStorm Communications s.r.o.&lt;br /&gt;Location : SK, Slovakia&lt;br /&gt;City : Bratislava, 02 -&lt;br /&gt;Latitude : 48°15'00" North&lt;br /&gt;Longitude : 17°11'67" East&lt;br /&gt;&lt;br /&gt;----Port 7212&lt;br /&gt;IP Address : 221.141.127.137 [ 221.141.127.137 ]&lt;br /&gt;ISP : Hanaro Telecom, Inc.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Ilsan, 21 -&lt;br /&gt;Latitude : 35°50'00" North&lt;br /&gt;Longitude : 129°43'33" East&lt;br /&gt;&lt;br /&gt;----Honey Port Web Surf&lt;br /&gt;IP Address : 61.69.212.98 [ C-61-69-212-98.for.connect.net.au ]&lt;br /&gt;ISP : AAPT Limited&lt;br /&gt;Organization : AAPT Limited&lt;br /&gt;Location : AU, Australia&lt;br /&gt;City : Tuggeranong, 01 -&lt;br /&gt;Latitude : 35°43'33" South&lt;br /&gt;Longitude : 149°15'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.236.179.1 [ 24-236-179-1.dhcp.mrqt.mi.charter.com ]&lt;br /&gt;ISP : CHARTER COMMUNICATIONS&lt;br /&gt;Organization : CHARTER COMMUNICATIONS&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houghton, MI 49931&lt;br /&gt;Latitude : 47°15'44" North&lt;br /&gt;Longitude : 88°64'71" West&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-7083566543304381674?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/7083566543304381674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=7083566543304381674' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7083566543304381674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7083566543304381674'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-22-2007.html' title='Cyber Center Report - October 22, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-6099656591806524630</id><published>2007-10-28T21:52:00.000-04:00</published><updated>2007-10-28T23:49:12.649-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 21, 2007</title><content type='html'>Black Lab Security Cyber Center Report&lt;br /&gt;Sunday, October 21, 2007 (9:17 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecuirty.com/"&gt;http://www.blacklabsecuirty.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Summary of Overnight Internet Activity&lt;br /&gt;--------------------------------------&lt;br /&gt;All previously reported probes/attacks from China, on all reported ports still continue from China. All previously reported probes/attacks from Korea, on all reported ports still continue from Korea.&lt;br /&gt;&lt;br /&gt;New probes/attacks on port 1026 from another unknown computer at 113.86.139.71. We can only conclude this is a government agency computer, which is intended to function on the Internet in a "stealth" environment, and is now broadcasting. Therefore, the computer must have been compromised because it is now broadcasting over the Internet. New probes/attacks on port 1433 from a new site in China, which is the Wuhan Institute of Science and Technology, and a probe/attack on port 1433 from inside the U.S., located in the Bronx, NY. New probes/attacks on port 1434 from Shanghai, China and Changsha, China. A new Probe/Attack on port 2968 was detected from Emeryville, CA. A new probe/attack on port 4715 was detected from East Northport, NY. A new probe/attack on port 4899 was detected from Portsmouth, VA. Port 25 continues to be probed/attacked from Taipei, Taiwan. BLSS Honey Pot Activity: One computer from within the U.S. attacked our honey pot for several hours last night. The attacking computer IP address was 74.138.235.20, located in Louisville, KY and executed programs in attempt to gain access by probing 59 different ports. The attempt to breach our honey pot was completely unsuccessful. None of the attempted exploits worked. The attacking computer ran programs against the following BLSS Honey Pot ports:&lt;br /&gt;&lt;br /&gt;13722, 27665, 829, 863, 1369, 914, 838, 834, 5902, 236, 50002, 2011, 479, 940, 27001, 974, 871, 267, 3005, 5432, 326, 1534, 1370, 32777, 15, 950, 559, 6667, 4480, 715, 1420, 468, 18, 61441, 664, 292, 32770, 98, 749, 7070, 19150, 665, 5302, 502, 1139, 129, 227, 331, 599, 249, 225, 1650, 1520, 692, 2032, 6009, 930, 1353&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;----Port 1026&lt;br /&gt;IP Address : 113.86.139.271&lt;br /&gt;: No Record&lt;br /&gt;&lt;br /&gt;----Port 1433&lt;br /&gt;IP Address : 211.67.58.203 [ 211.67.58.203 ]&lt;br /&gt;ISP : China Education and Research Network&lt;br /&gt;Organization : Wuhan Institute of Science and Technology&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Wuhan, 12 -&lt;br /&gt;Latitude : 30°58'33" North&lt;br /&gt;Longitude : 114°26'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 69.119.135.173 [ ool-457787ad.dyn.optonline.net ]&lt;br /&gt;ISP : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Bronx, NY -&lt;br /&gt;Latitude : 40°84'99" North&lt;br /&gt;Longitude : 73°87'69" West&lt;br /&gt;&lt;br /&gt;----Port 1434&lt;br /&gt;IP Address : 61.134.56.18 [ 61.134.56.18 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : Data Communication Division&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Shanghai, 23 -&lt;br /&gt;Latitude : 31°00'50" North&lt;br /&gt;Longitude : 121°40'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 58.20.228.52 [ 58.20.228.52 ]&lt;br /&gt;ISP : CNC Group HuNan province network&lt;br /&gt;Organization : CNC Group HuNan province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Changsha, 11 -&lt;br /&gt;Latitude : 28°17'92" North&lt;br /&gt;Longitude : 113°11'36" East&lt;br /&gt;&lt;br /&gt;----Port 2968&lt;br /&gt;IP Address : 69.107.113.217 [ adsl-69-107-113-217.dsl.pltn13.pacbell.net ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : SBC Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Emeryville, CA -&lt;br /&gt;Latitude : 37°83'42" North&lt;br /&gt;Longitude : 122°28'97" West&lt;br /&gt;&lt;br /&gt;----Port 4715&lt;br /&gt;IP Address : 69.118.128.82 [ ool-45768052.dyn.optonline.net ]&lt;br /&gt;ISP : Optimum Online (Cablevision Systems)&lt;br /&gt;Organization : Optimum Online (Cablevision Systems)&lt;br /&gt;Location : US, United States&lt;br /&gt;City : East Northport, NY 11731&lt;br /&gt;Latitude : 40°86'18" North&lt;br /&gt;Longitude : 73°31'51" West&lt;br /&gt;&lt;br /&gt;----Port 25&lt;br /&gt;IP Address : 122.116.17.133 [ 122-116-17-133.HINET-IP.hinet.net ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Chunghwa Telecom Data communication Business Group&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;---4899&lt;br /&gt;IP Address : 71.241.11.185 [ pool-71-241-11-185.norf.east.verizon.net ]&lt;br /&gt;ISP : Verizon Internet Services&lt;br /&gt;Organization : Verizon Internet Services&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Portsmouth, VA -&lt;br /&gt;Latitude : 36°83'39" North&lt;br /&gt;Longitude : 76°34'00" West&lt;br /&gt;&lt;br /&gt;----Attack On Honey Pot&lt;br /&gt;IP Address : 74.138.235.20 [ 74-138-235-20.dhcp.insightbb.com ]&lt;br /&gt;ISP : INSIGHT COMMUNICATIONS COMPANY, L.P.&lt;br /&gt;Organization : Insight Communications Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Louisville, KY -&lt;br /&gt;Latitude : 38°20'85" North&lt;br /&gt;Longitude : 85°69'18" West&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-6099656591806524630?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/6099656591806524630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=6099656591806524630' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6099656591806524630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/6099656591806524630'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-21-2007.html' title='Cyber Center Report - October 21, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-9049502408592134977</id><published>2007-10-28T21:49:00.000-04:00</published><updated>2007-10-28T23:49:12.650-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 20, 2007</title><content type='html'>Black Lab Security Cyber Center Report&lt;br /&gt;Saturday, October 20, 2007 (10:12 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecuirty.com/"&gt;http://www.blacklabsecuirty.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Summary of Overnight Internet Activity&lt;br /&gt;--------------------------------------&lt;br /&gt;All previously reported probes/attacks from China, on all reported ports still continue from China. All previously reported probes/attacks from Korea, on all reported ports still continue from Korea.&lt;br /&gt;&lt;br /&gt;New probes/attacks were detected on port 1026 from Mexico, U.S. Naval Ocean Systems Center, France and Korea (new site in Korea), which all of the new sites on port 1026 are the same characteristics as previously recorded (and on-going) with China.&lt;br /&gt;&lt;br /&gt;Elli Lilly was detected on port 1026 again. Canada was detected on ports 1026, 1027 and 1028, probing/attacking (sequentially) on all three ports.&lt;br /&gt;&lt;br /&gt;A new computer in Dublin, Ireland was detected probing/attacking on port 5900.&lt;br /&gt;&lt;br /&gt;Japan and Oman were detected probing/attack on port 1434. One new site in the U.S. and was probing/attacking on port 25.&lt;br /&gt;&lt;br /&gt;One new site in Canada was probing/attacking on port 21.&lt;br /&gt;&lt;br /&gt;Honey Pot Activity: Four computers from four different countries (U.S., Canada France and United Kingdom) connected to our BLSS Honey Pot through port 80. But each connection was from an actual user "surfing" and performing an analysis of our honey pot. No attacks were launched. The U.S., Canada, France and the United Kingdom (all) had a user manually reviewing our web site and it's sub-systems via Port 80. Each user performed a careful analysis of our honey pot.&lt;br /&gt;&lt;br /&gt;Port 1026 (New)&lt;br /&gt;--------------&lt;br /&gt;Mexico - Montevideo&lt;br /&gt;U.S. - Naval Ocean Systems Center&lt;br /&gt;France - Bordeaux&lt;br /&gt;Korea - unknown&lt;br /&gt;&lt;br /&gt;Port 1026 (Recurring)&lt;br /&gt;--------------------&lt;br /&gt;U.S. - Indianapolis - Eli Lilly and Company&lt;br /&gt;&lt;br /&gt;Port 1026, 1027 and 1028 (Recurring)&lt;br /&gt;------------------------------------&lt;br /&gt;Canada - unknown&lt;br /&gt;&lt;br /&gt;Port 1024 (New)&lt;br /&gt;--------------&lt;br /&gt;U.S. - Houston, TX&lt;br /&gt;&lt;br /&gt;Port 5900 (New)&lt;br /&gt;---------------&lt;br /&gt;Ireland - Dublin&lt;br /&gt;&lt;br /&gt;Port 3128 (New)&lt;br /&gt;---------------&lt;br /&gt;Korea - Seocho&lt;br /&gt;&lt;br /&gt;Port 1434 (New)&lt;br /&gt;---------------&lt;br /&gt;Japan - Unknown&lt;br /&gt;Oman - Muscat&lt;br /&gt;&lt;br /&gt;Port 1434 (Recurring)&lt;br /&gt;---------------------&lt;br /&gt;Korea - Seocho&lt;br /&gt;&lt;br /&gt;Port 25 (New)&lt;br /&gt;-------------&lt;br /&gt;U.S. - Kansas - Wichita&lt;br /&gt;&lt;br /&gt;Port 21 (New)&lt;br /&gt;-------------&lt;br /&gt;Canada - Calgary&lt;br /&gt;&lt;br /&gt;Port 3072 and 1024 continuous&lt;br /&gt;----------------------------&lt;br /&gt;U.S. - Houston, TX&lt;br /&gt;&lt;br /&gt;Direct Activity On BLSS Honey Pot&lt;br /&gt;---------------------------------&lt;br /&gt;France&lt;br /&gt;United Kingdom&lt;br /&gt;Canada&lt;br /&gt;U.S.&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP&lt;br /&gt;address:&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;OrgName: Latin American and Caribbean IP address Regional Registry&lt;br /&gt;OrgID: LACNIC&lt;br /&gt;Address: Rambla Republica de Mexico 6125&lt;br /&gt;City: Montevideo&lt;br /&gt;StateProv:&lt;br /&gt;PostalCode: 11400&lt;br /&gt;Country: UY&lt;br /&gt;&lt;br /&gt;IP Address : 40.220.102.110 [ 40.220.102.110 ]&lt;br /&gt;ISP : Eli Lilly and Company&lt;br /&gt;Organization : Eli Lilly and Company&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Indianapolis, IN 46285&lt;br /&gt;Latitude : 39°77'95" North&lt;br /&gt;Longitude : 86°13'28" West&lt;br /&gt;&lt;br /&gt;IP Address : 140.54.211.52 [ 140.54.211.52 ]&lt;br /&gt;ISP : Naval Ocean Systems Center&lt;br /&gt;Organization : Naval Ocean Systems Center&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 82.66.13.50 [ cau33-1-82-66-13-50.fbx.proxad.net ]&lt;br /&gt;ISP : Proxad&lt;br /&gt;Organization : Proxad / Free SAS&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Bordeaux, 97 -&lt;br /&gt;Latitude : 44°83'33" North&lt;br /&gt;Longitude : 0°56'67" West&lt;br /&gt;&lt;br /&gt;IP Address : 58.77.32.183 [ 58.77.32.183 ]&lt;br /&gt;ISP : Dacom&lt;br /&gt;Organization : POWERCOMM&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;----Port 1026, 1027, 1028&lt;br /&gt;IP Address : 24.64.40.117 [ 24.64.40.117 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;br /&gt;&lt;br /&gt;---- Port 1024&lt;br /&gt;IP Address : 67.15.83.36 [ ronaldsrecordclub.com ]&lt;br /&gt;ISP : Everyones Internet&lt;br /&gt;Organization : Everyones Internet&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houston, TX 77060&lt;br /&gt;Latitude : 29°93'42" North&lt;br /&gt;Longitude : 95°40'57" West&lt;br /&gt;&lt;br /&gt;--- port 5900&lt;br /&gt;IP Address : 87.192.228.237 [ 87.192.228.237 ]&lt;br /&gt;ISP : Irish Broadband Internet Services Limited.&lt;br /&gt;Organization : Irish Broadband Internet Services Limited.&lt;br /&gt;Location : IE, Ireland&lt;br /&gt;City : Dublin, 07 -&lt;br /&gt;Latitude : 53°33'31" North&lt;br /&gt;Longitude : 6°24'89" West&lt;br /&gt;&lt;br /&gt;--- Port 3128&lt;br /&gt;IP Address : 218.50.1.119 [ 218.50.1.119 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;--- port 1434&lt;br /&gt;IP Address : 116.80.88.168 [ ntsitm382168.sitm.nt.ftth.ppp.infoweb.ne.jp ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : InfoWeb(Fujitsu Ltd.)&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 82.178.22.22 [ 82.178.22.22 ]&lt;br /&gt;ISP : Oman&lt;br /&gt;Organization : Muscat Ltd&lt;br /&gt;Location : OM, Oman&lt;br /&gt;City : Muscat, 06 -&lt;br /&gt;Latitude : 23°61'33" North&lt;br /&gt;Longitude : 58°59'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.232.95.60 [ 218.232.95.60 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Hanaro Telecom Co.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;---- Port 25&lt;br /&gt;IP Address : 216.174.63.97 [ 97.gotexchange.com ]&lt;br /&gt;ISP : TELCOVE&lt;br /&gt;Organization : Kansas Hosting, LLC&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Wichita, KS -&lt;br /&gt;Latitude : 37°69'10" North&lt;br /&gt;Longitude : 97°32'92" West&lt;br /&gt;&lt;br /&gt;--- Port 21&lt;br /&gt;IP Address : 72.2.24.134 [ h72-2-24-134.bigpipeinc.com ]&lt;br /&gt;ISP : Big Pipe&lt;br /&gt;Organization : Big Pipe&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Calgary, AB t2p4l4&lt;br /&gt;Latitude : 51°08'33" North&lt;br /&gt;Longitude : 114°08'33" West&lt;br /&gt;&lt;br /&gt;--- Port 3072, 1024 continous&lt;br /&gt;IP Address : 67.15.83.36 [ ronaldsrecordclub.com ]&lt;br /&gt;ISP : Everyones Internet&lt;br /&gt;Organization : Everyones Internet&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houston, TX 77060&lt;br /&gt;Latitude : 29°93'42" North&lt;br /&gt;Longitude : 95°40'57" West&lt;br /&gt;&lt;br /&gt;---- Port 80 Surf Of The Honey Pot&lt;br /&gt;IP Address : 213.186.44.52 [ siomproject.com ]&lt;br /&gt;ISP : Ovh Systems&lt;br /&gt;Organization : OVH SAS&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Roubaix, B4 -&lt;br /&gt;Latitude : 50°70'00" North&lt;br /&gt;Longitude : 3°16'67" East&lt;br /&gt;&lt;br /&gt;IP Address : 4.91.128.52 [&lt;br /&gt;dialup-4.91.128.52.Dial1.Philadelphia1.Level3.net ]&lt;br /&gt;ISP : Level 3 Communications&lt;br /&gt;Organization : Level 3 Communications&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - - (Appoximately Colorado)&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 82.20.37.157 [ client-82-20-37-157.manc.adsl.virgin.net ]&lt;br /&gt;ISP : NTL Internet&lt;br /&gt;Organization : NTL Internet&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 99.230.53.49 [&lt;br /&gt;CPE0012171a58a3-CM001947479cb0.cpe.net.cable.rogers.com ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Rogers Cable&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 60°00'00" North&lt;br /&gt;Longitude : 95°00'00" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-9049502408592134977?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/9049502408592134977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=9049502408592134977' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/9049502408592134977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/9049502408592134977'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/october-20-2007-cyber-report.html' title='Cyber Center Report - October 20, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-162678064348558860</id><published>2007-10-28T21:35:00.000-04:00</published><updated>2007-10-28T23:49:12.651-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Attacking IP Addresses and Ports with Focus on China for Week Ending 19 Oct 2007</title><content type='html'>Black Lab Security Cyber Center Report&lt;br /&gt;October 19, 2007 (09:00 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc.&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacksecurity.com/"&gt;http://www.blacksecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Our BLSS Cyber Report is experimenting with a new format. As you have requested and will see below, more categories with less narrative in an attempt to get directly to the point.&lt;br /&gt;&lt;br /&gt;Summary of Overnight Internet Activity&lt;br /&gt;-----------------------------------------------------&lt;br /&gt;&lt;br /&gt;1) New probes/attacks were detected on port 1026 from Italy and the Univ. Of Utah (same characteristics as previously recorded with China).&lt;br /&gt;2) Continued probes/attacks on port 1026 were sustained by China, Germany (Daimler Chrysler - Automobile Corporation), France and Israel.&lt;br /&gt;3) New computers with no known record have begun to probe/attack on port 1026. The first computer with no record is 162.226.138.24 and was located by satellite on the coast of the United Kingdom. The second computer with no record is 96.84.183.29 and could NOT be located by satellite. Both internet addresses (computers) with no records are now broadcasting over the Internet. We can only conclude these are government agency computers, which have been configured to remain 100% stealth (silent) while on the Internet and have been "hi-jacked" over port 1026 and now broadcasting.&lt;br /&gt;4) New probe/attack on port 1024 from Turkey.&lt;br /&gt;5) New Probe/Attack on Port 21 from Brazil, which BLSS detected and logged two sites within Brazil executing their probe/attack on port 21 almost at the same exact time.&lt;br /&gt;6) Finally, three computers connected to our BLSS Honey Port through port 80, then began to manually attack our honey pot. When the manual attacks were not successful, they executed a series of programs, which scanned over 2000 possible ports in an attempt to gain entry and hack our honey port. The hackers connected to our honey pot via port 80, remain connected while they executed their programs, then disconnected from our honey port after about 30 minutes of continuous penetration attempts.&lt;br /&gt;&lt;br /&gt;New on Port 1026&lt;br /&gt;-----------------------&lt;br /&gt;Italy&lt;br /&gt;Univ Of Utah (U.S.).&lt;br /&gt;&lt;br /&gt;Previously recorded and still probing/attacking Port 1026&lt;br /&gt;----------------------------------------------------------------------------&lt;br /&gt;More computers in the U.K. with no record Germany France Israel&lt;br /&gt;&lt;br /&gt;New on Port 1024&lt;br /&gt;-----------------------&lt;br /&gt;Turkey&lt;br /&gt;&lt;br /&gt;New on Port 21&lt;br /&gt;---------------------&lt;br /&gt;Brazil - detected two sites coordinated together probing/attacking port 21&lt;br /&gt;&lt;br /&gt;New Probes/Attacks from China&lt;br /&gt;-----------------------------&lt;br /&gt;New probe/attack from China on port 949&lt;br /&gt;New probe/attack from China on port 22&lt;br /&gt;New probe/attack from China on port 2967 New probe/attack from China on port 42&lt;br /&gt;&lt;br /&gt;New Sites Detected From China&lt;br /&gt;-----------------------------&lt;br /&gt;New probe/attack from China on port 1434 from a new IP New probe/attack from China on port 2967 from a new IP New probe/attack from Rep Of Korea on port 4899&lt;br /&gt;&lt;br /&gt;New Probes/Attacks from Korea&lt;br /&gt;-----------------------------&lt;br /&gt;New probe/attack from Rep Of Korea on port 7212 - same as previously recorded with China&lt;br /&gt;&lt;br /&gt;Noticeably Higher Volume Than Normal&lt;br /&gt;------------------------------------&lt;br /&gt;Noticeably high volume of probes/attacks on port 8180 from U.S.&lt;br /&gt;Noticeably high volume of probes/attacks on port 3128 from Korea&lt;br /&gt;&lt;br /&gt;Hackers Connecting And Attacking Our BLSS Honey Pot&lt;br /&gt;---------------------------------------------------&lt;br /&gt;Actually connecting through port 80, then attacking our honey pot:&lt;br /&gt;Canada&lt;br /&gt;U.S. - Somewhere approximately in Colorado&lt;br /&gt;&lt;br /&gt;Hackers Attack Summary&lt;br /&gt;----------------------&lt;br /&gt;The hackers connected via port 80, then manually executed a series of attacks. Once the manual attacks were not successful, the hackers executed a series of program, which scanned/probed and attempting to hack by accessing over 2000 ports. While the port attempts list is too long to actually list in this e-mail, some of the ports probes/attacked by the hackers are the following:&lt;br /&gt;&lt;br /&gt;80, 1, 35019, 44285, 1026, 4137, 777, 5550, 4987, 830, 941, 716, 829, 49400, 61, 65, 295, 1355, 985, 680, 1664, 798, 1478, 704, 407, 1413, 902, 5060, 9991, 6147, 6006, 1984, 6112, 846, 2040, 150, 178, 297, 71, 20, 2044, 541, 1987, 910, 18184, 883, 1399, 1430, 329, 1004, 1494, 6142, 364, 528, 124, 4480, 791, 812, 1441, 640, 1352, 478, 431, 1025, 748, 8888, 3397, 1472, 347, 426, 27010, 794, 43, 274, 2628, 1350, 3455, 89, 13717, 341, 689, 500, 1485, 230, 292, 10000, 730, 784, 368, 792, 2602, 396, etc. etc. etc..... approximately 2000 ports (some scanned probed/attacked more than once)&lt;br /&gt;&lt;br /&gt;Below is a listing of the specific details on each port probe/attack and IP address:&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;IP Address : 90.131.246.209 [ d90-131-246-209.cust.tele2.it ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Tele2 Italy S.A&lt;br /&gt;Location : IT, Italy&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 42°83'33" North&lt;br /&gt;Longitude : 12°83'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 155.98.155.83 [ 155.98.155.83 ]&lt;br /&gt;ISP : University of Utah&lt;br /&gt;Organization : University of Utah&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Salt Lake City, UT 84108&lt;br /&gt;Latitude : 40°78'55" North&lt;br /&gt;Longitude : 111°73'67" West&lt;br /&gt;&lt;br /&gt;162.226.138.24 [ 162.226.138.24 ]&lt;br /&gt;No Record&lt;br /&gt;&lt;br /&gt;IP Address : 96.84.183.29 [ 96.84.183.29 ]&lt;br /&gt;No Record&lt;br /&gt;&lt;br /&gt;IP Address : 194.164.169.63 [ 194.164.169.63 ]&lt;br /&gt;ISP : Mistral Internet&lt;br /&gt;Organization : Mistral Internet&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : Brighton, E2 -&lt;br /&gt;Latitude : 50°83'33" North&lt;br /&gt;Longitude : 0°15'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 30.182.61.121 [ 30.182.61.121 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 53.139.242.162 [ 53.139.242.162 ]&lt;br /&gt;ISP : DaimlerChrysler AG&lt;br /&gt;Organization : DAIMLERCHRYSLER AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Stuttgart, 01 -&lt;br /&gt;Latitude : 48°76'67" North&lt;br /&gt;Longitude : 9°18'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 86.67.144.204 [ 204.144.67-86.rev.gaoland.net ]&lt;br /&gt;ISP : LDCOM&lt;br /&gt;Organization : LDCOM&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Billancourt, A8 -&lt;br /&gt;Latitude : 48°83'33" North&lt;br /&gt;Longitude : 2°25'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 82.166.13.50 [ 82-166-13-50.barak-online.net ]&lt;br /&gt;ISP : Barak I.T.C&lt;br /&gt;Organization : Barak I.T.C&lt;br /&gt;Location : IL, Israel&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 31°50'00" North&lt;br /&gt;Longitude : 34°75'00" East&lt;br /&gt;&lt;br /&gt;---- Port 1024&lt;br /&gt;IP Address : 85.111.0.240 [ 85.111.0.240 ]&lt;br /&gt;ISP : Turk Telekom&lt;br /&gt;Organization : Turk Telekom&lt;br /&gt;Location : TR, Turkey&lt;br /&gt;City : Ankara, 68 -&lt;br /&gt;Latitude : 39°92'72" North&lt;br /&gt;Longitude : 32°86'44" East&lt;br /&gt;&lt;br /&gt;--- Port 8180 (identified due to continuous hits)&lt;br /&gt;IP Address : 208.109.78.71 [ wh120.prod.mesa1.secureserver.net ]&lt;br /&gt;ISP : Go Daddy Software&lt;br /&gt;Organization : GoDaddy.com&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Scottsdale, AZ 85260&lt;br /&gt;Latitude : 33°61'19" North&lt;br /&gt;Longitude : 111°89'07" West&lt;br /&gt;&lt;br /&gt;IP Address : 72.20.41.204 [ yourescortagency.com ]&lt;br /&gt;ISP : Staminus Communications&lt;br /&gt;Organization : Staminus Communications&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fullerton, CA 92832&lt;br /&gt;Latitude : 33°86'82" North&lt;br /&gt;Longitude : 117°92'93" West&lt;br /&gt;&lt;br /&gt;---- Port 949&lt;br /&gt;IP Address : 58.56.77.122 [ 58.56.77.122 ]&lt;br /&gt;ISP : CHINANET shandong province network&lt;br /&gt;Organization : CHINANET shandong province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Jinan, 25 -&lt;br /&gt;Latitude : 36°66'83" North&lt;br /&gt;Longitude : 116°99'72" East&lt;br /&gt;&lt;br /&gt;IP Address : 218.92.50.85 [ 218.92.50.85 ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;---- Port22&lt;br /&gt;IP Address : 221.122.59.2 [ 221.122.59.2 ]&lt;br /&gt;ISP : CETC-CHINACOMM COMMUNICATIONS Co.,Ltd.&lt;br /&gt;Organization : CETC-CHINACOMM COMMUNICATIONS Co.,Ltd.&lt;br /&gt;Location : CN, China&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 35°00'00" North&lt;br /&gt;Longitude : 105°00'00" East&lt;br /&gt;&lt;br /&gt;---- Port 4899&lt;br /&gt;IP Address : 122.38.90.165 [ 122.38.90.165 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : POWERCOMM&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" East&lt;br /&gt;&lt;br /&gt;---- Port 2967&lt;br /&gt;IP Address : 60.174.69.246 [ 60.174.69.246 ]&lt;br /&gt;ISP : CHINANET Anhui province network&lt;br /&gt;Organization : CHINANET Anhui province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Hefei, 01 -&lt;br /&gt;Latitude : 31°86'39" North&lt;br /&gt;Longitude : 117°28'08" East&lt;br /&gt;&lt;br /&gt;---- Port 42&lt;br /&gt;IP Address : 210.42.88.252 [ 210.42.88.252 ]&lt;br /&gt;ISP : China Education and Research Network&lt;br /&gt;Organization : Hubei Communications School&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Wuhan, 12 -&lt;br /&gt;Latitude : 30°58'33" North&lt;br /&gt;Longitude : 114°26'67" East&lt;br /&gt;&lt;br /&gt;---- port 3128&lt;br /&gt;IP Address : 218.50.1.119 [ 218.50.1.119 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;---- Port 7212&lt;br /&gt;IP Address : 59.18.87.10 [ 59.18.87.10 ]&lt;br /&gt;ISP : Korea Telecom&lt;br /&gt;Organization : Korea Telecom&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 37°00'00" North&lt;br /&gt;Longitude : 127°50'00" E&lt;br /&gt;&lt;br /&gt;---- Port 1434&lt;br /&gt;IP Address : 218.108.70.246 [ 218.108.70.246 ]&lt;br /&gt;ISP : WASU TV &amp;amp; Communication Holding Co.,Ltd.&lt;br /&gt;Organization : wangJiangFeng&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Chaoyang, 19 -&lt;br /&gt;Latitude : 41°57'03" North&lt;br /&gt;Longitude : 120°45'86" East&lt;br /&gt;&lt;br /&gt;---- Port 2967&lt;br /&gt;IP Address : 202.113.121.152 [ 202.113.121.152 ]&lt;br /&gt;ISP : China Education and Research Network&lt;br /&gt;Organization : Heibei University of Technology&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Tianjin, 28 -&lt;br /&gt;Latitude : 39°14'22" North&lt;br /&gt;Longitude : 117°17'67" East&lt;br /&gt;&lt;br /&gt;---- Port 21&lt;br /&gt;IP Address : 200.252.113.5 [ 200.252.113.5 ]&lt;br /&gt;ISP : EMBRATEL-EMPRESA BRASILEIRA DE TELECOMUNICAÇÕES SA&lt;br /&gt;Organization : CESB - Centro de Educacao Superior de Brasilia&lt;br /&gt;Location : BR, Brazil&lt;br /&gt;City : Brasília, 07 -&lt;br /&gt;Latitude : 15°78'33" South&lt;br /&gt;Longitude : 47°91'67" West&lt;br /&gt;&lt;br /&gt;IP Address : 200.102.170.171 [200-102-170-171.paemt705.dsl.brasiltelecom.net.br ]&lt;br /&gt;ISP : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Organization : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Location : BR, Brazil&lt;br /&gt;City : Porto Alegre, 23 -&lt;br /&gt;Latitude : 30°03'33" South&lt;br /&gt;Longitude : 51°20'00" West&lt;br /&gt;&lt;br /&gt;---- Port 80, then attacking our honey pot&lt;br /&gt;IP Address : 70.68.54.161 [ S01060014a580e595.vf.shawcable.net ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Victoria, BC -&lt;br /&gt;Latitude : 48°43'33" North&lt;br /&gt;Longitude : 123°35'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 69.157.7.252 [ bas2-hamilton14-1167919100.dsl.bell.ca ]&lt;br /&gt;ISP : Bell Canada&lt;br /&gt;Organization : Sympatico&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Hamilton, ON -&lt;br /&gt;Latitude : 43°25'00" North&lt;br /&gt;Longitude : 79°83'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 4.91.133.221 [dialup-4.91.133.221.Dial1.Philadelphia1.Level3.net ]&lt;br /&gt;ISP : Level 3 Communications&lt;br /&gt;Organization : Level 3 Communications&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Thursday, October 18, 2007 (10:00 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc.&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;BLSS Cyber Center Observations About Chinese Sites&lt;br /&gt;&lt;br /&gt;In performing an in-depth analysis of the Chinese probes/attacks, we have reached the following conclusion:&lt;br /&gt;&lt;br /&gt;Of all the active Chinese sites, the top nine most active sites, include two sites that are much more active than the remaining seven IP sites. The two sites which "break the curve" and are continuously probing/attacking every three-to-five minutes are the following:&lt;br /&gt;&lt;br /&gt;Site Port&lt;br /&gt;------------- ----&lt;br /&gt;121.18.13.107 7212&lt;br /&gt;121.18.12.197 7212&lt;br /&gt;&lt;br /&gt;The remaining seven sites probing/attacking are the following:&lt;br /&gt;&lt;br /&gt;Site Port&lt;br /&gt;-------------- ----&lt;br /&gt;221.208.208.83 1027&lt;br /&gt;221.208.208.91 1027&lt;br /&gt;221.208.208.95 1026 and 1027&lt;br /&gt;221.208.208.98 1026&lt;br /&gt;202.97.238.202 1026&lt;br /&gt;218.50.1.119 3128&lt;br /&gt;222.239.255.43 1080&lt;br /&gt;&lt;br /&gt;We have detected a new computer in France joining the probe/attack on Port 1026. The information on the French computer is the following:&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;IP Address : 82.66.13.50 [ cau33-1-82-66-13-50.fbx.proxad.net ]&lt;br /&gt;ISP : Proxad&lt;br /&gt;Organization : Proxad / Free SAS&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Bordeaux, 97 -&lt;br /&gt;Latitude : 44°83'33" North&lt;br /&gt;Longitude : 0°56'67" West&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Thursday, October 18, 2007 (5:18 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1) BLSS has detected and observed a major shift overnight, to a more positive period of overall internet activity. All probes/attacks from China still continue, but many Chinese sites appear to be much less frequent.&lt;br /&gt;2) A few Chinese sites are still as aggressive, but not all Chinese sites are exhibiting the same level of aggressive activity.&lt;br /&gt;3) The best news is that there has been a "shift" in computers participating in the probe/attack of ports 1026 (and at times 1027) and Port 1434. The "shift" is all new countries, (except for the U.S.), which now includes Japan, Israel, Taiwan, Switzerland and Sweden.&lt;br /&gt;4) The worst news of the night, is that Performance Systems International (U.S.), Morgan Stanley Group (U.S.), Oracle (U.S.), Oracle Japan and Sweden's "The Swatch Group" are now participating in the probe/attack on port 1026. South Korea is now probing/attacking on Port 22.&lt;br /&gt;&lt;br /&gt;We have utilized a satellite IP address locator, &lt;a href="http://www.seomoz.org/ip2loc"&gt;http://www.seomoz.org/ip2loc&lt;/a&gt;, in an attempt to identify the IP address 154.191.242.60 (yesterday's Cyber Report) and it is physically located on the coast of the United Kingdom. The location has been found, but the identity is still unknown.&lt;br /&gt;&lt;br /&gt;In our professional opinion, last night's overall Internet activity is a major improvement in compared to Tuesday night's Internet activity.&lt;br /&gt;&lt;br /&gt;Port 1026 (and at times port 1027)&lt;br /&gt;----------------------------------&lt;br /&gt;&lt;br /&gt;Japan&lt;br /&gt;U.S.&lt;br /&gt;Israel&lt;br /&gt;Taiwan&lt;br /&gt;Switzerland&lt;br /&gt;&lt;br /&gt;Port 1434&lt;br /&gt;---------&lt;br /&gt;Sweden&lt;br /&gt;&lt;br /&gt;Port 22&lt;br /&gt;-------&lt;br /&gt;South Korea&lt;br /&gt;&lt;br /&gt;The specific details on each IP is below.&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;IP Address : 133.160.34.234 [ 133.160.34.234 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 24.211.81.202 [ cpe-024-211-081-202.sc.res.rr.com ]&lt;br /&gt;ISP : Road Runner&lt;br /&gt;Organization : Road Runner&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Mamers, NC 27552&lt;br /&gt;Latitude : 35°42'01" North&lt;br /&gt;Longitude : 78°93'43" West&lt;br /&gt;&lt;br /&gt;IP Address : 67.116.31.77 [ adsl-67-116-31-77.dsl.snfc21.pacbell.net ]&lt;br /&gt;ISP : SBC Internet Services&lt;br /&gt;Organization : PRINT SMITH&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Moraga, CA -&lt;br /&gt;Latitude : 37°83'81" North&lt;br /&gt;Longitude : 122°10'26" West&lt;br /&gt;&lt;br /&gt;IP Address : 133.121.131.115 [ 133.121.131.115 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 38.66.244.63 [ 38.66.244.63 ]&lt;br /&gt;ISP : Performance Systems International&lt;br /&gt;Organization : Performance Systems International&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Washington, DC 20007&lt;br /&gt;Latitude : 38°91'44" North&lt;br /&gt;Longitude : 77°07'63" West&lt;br /&gt;&lt;br /&gt;IP Address : 82.166.13.50 [ 82-166-13-50.barak-online.net ]&lt;br /&gt;ISP : Barak I.T.C&lt;br /&gt;Organization : Barak I.T.C&lt;br /&gt;Location : IL, Israel&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 31°50'00" North&lt;br /&gt;Longitude : 34°75'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 138.20.91.183 [ 138.20.91.183 ]&lt;br /&gt;ISP : Morgan Stanley Group&lt;br /&gt;Organization : Morgan Stanley Group&lt;br /&gt;Location : US, United States&lt;br /&gt;City : New York, NY 10036&lt;br /&gt;Latitude : 40°76'05" North&lt;br /&gt;Longitude : 73°99'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 148.87.242.224 [&lt;br /&gt;reserved-for-dhcp-148-87-242-224.oracle.com ]&lt;br /&gt;ISP : Oracle Datenbanksysteme GmbH&lt;br /&gt;Organization : Oracle Datenbanksysteme GmbH&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Redwood City, CA 94065&lt;br /&gt;Latitude : 37°53'31" North&lt;br /&gt;Longitude : 122°24'71" West&lt;br /&gt;&lt;br /&gt;IP Address : 124.11.42.31 [ 124-11-42-31.static.tfn.net.tw ]&lt;br /&gt;ISP : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Organization : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;IP Address : 21.137.44.14 [ 21.137.44.14 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 149.133.181.115 [ 149.133.181.115 ]&lt;br /&gt;ISP : THE SWATCH GROUP&lt;br /&gt;Organization : THE SWATCH GROUP&lt;br /&gt;Location : CH, Switzerland&lt;br /&gt;City : Biel, 05 -&lt;br /&gt;Latitude : 47°16'67" North&lt;br /&gt;Longitude : 7°25'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 146.56.56.108 [ 146.56.56.108 ]&lt;br /&gt;ISP : Oracle Corporation Japan&lt;br /&gt;Organization : Oracle Corporation Japan&lt;br /&gt;Location : JP, Japan&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 36°00'00" North&lt;br /&gt;Longitude : 138°00'00" East&lt;br /&gt;&lt;br /&gt;---- Port 1434&lt;br /&gt;IP Address : 84.112.179.164 [ chello084112179164.31.11.vie.surfer.at ]&lt;br /&gt;ISP : Chello Broadband GmbH&lt;br /&gt;Organization : Chello Broadband GmbH&lt;br /&gt;Location : SE, Sweden&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 62°00'00" North&lt;br /&gt;Longitude : 15°00'00" East&lt;br /&gt;&lt;br /&gt;---- Port 22&lt;br /&gt;IP Address : 58.120.21.229 [ 58.120.21.229 ]&lt;br /&gt;ISP : Hanaro Telecom, Inc.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seoul, 11 -&lt;br /&gt;Latitude : 37°56'64" North&lt;br /&gt;Longitude : 126°99'97" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Wednesday, October 17, 2007 (5:41 PM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Because ports 1026 and 1027 were the most common ports exploited overnight, we decided to provide an end-of-day report on these specific ports.&lt;br /&gt;&lt;br /&gt;The most interesting probe/attack, comes from an IP address of 154.191.242.60, which is not recorded in any of the 10 "whois" communication databases BLSS utilizes as reference at this time. It is an actual IP address and it is conducting probes/attacks on port 1026 UDP. We can only conclude that the IP must belong to a computer within a government agency.&lt;br /&gt;&lt;br /&gt;We have detected and observed two new countries probing/attacking on the following ports (same as previously reported by China):&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;IP Address : 161.71.93.139 [ ip-161-71-0-0.euro.3com.com ]&lt;br /&gt;ISP : Isolan House&lt;br /&gt;Organization : Isolan House&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : Hemel Hempstead, F8 -&lt;br /&gt;Latitude : 51°75'00" North&lt;br /&gt;Longitude : 0°46'67" West&lt;br /&gt;&lt;br /&gt;---- Port 1027&lt;br /&gt;IP Address : 82.166.13.50 [ 82-166-13-50.barak-online.net ]&lt;br /&gt;ISP : Barak I.T.C&lt;br /&gt;Organization : Barak I.T.C&lt;br /&gt;Location : IL, Israel&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 31°50'00" North&lt;br /&gt;Longitude : 34°75'00" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Wednesday, October 17, 2007 (9:00 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1) BLSS has detected and observed the worst night of probes/attacks since we started reported internet activity.&lt;br /&gt;2) All probes/attacks from China continue and the frequency of China probes/attacks has gotten much shorter (worse) and China is "bombarding" the U.S. internet infrastructure.&lt;br /&gt;3) It is also the same scenario for South Korea. South Korea is probing/attacking with a greater frequency (same previously reported probes/attacks).&lt;br /&gt;4) Within a 15 hour period since yesterday, many other countries have "suddenly started" probing/attacking the same ports as China/South Korea.&lt;br /&gt;&lt;br /&gt;In summary, after days of continuous probes/attacks from China/South Korea, suddenly within a 15 hour period we (BLSS) have detected and observed Argentina, New Zealand, Russia, Belgium, Mexico, Africa, India, Taiwan, Sweden, Oman, Spain, Brazil and Germany joined in on the same probes/attacks on the U.S. Internet infrastructure. This does not include the U.S. computers that have joined the same attack, including a computer within the U.S. Army's Information Systems headquarters located at Fort Huachuca, AZ.&lt;br /&gt;&lt;br /&gt;As the U.S. is concerned about a possible penetration into U.S. power (electric) companies, it has happened below with WISCONSIN ENERGY CONSERVATION CORPORATION (port 2967).&lt;br /&gt;&lt;br /&gt;Within the past 15 hours, the following countries/organizations have joined in probing/attacking the U.S. Internet infrastructure:&lt;br /&gt;&lt;br /&gt;Port 1026&lt;br /&gt;---------&lt;br /&gt;140.200.226.166 New Zealand&lt;br /&gt;17.202.238.133 U.S. - APPLE COMPUTER&lt;br /&gt;17.91.7.155 U.S. - APPLE COMPUTER&lt;br /&gt;17.202.238.133 Russia Russian Federation&lt;br /&gt;190.174.3.188 Argentina&lt;br /&gt;97.70.91.231 U.S. - Bright Networks, Brandon, FL&lt;br /&gt;152.18.12.22 U.S. Univ Of North Carolina At Asheville&lt;br /&gt;147.93.101.5 Belgium&lt;br /&gt;200.66.140.237 Mexico&lt;br /&gt;35.16.46.36 U.S. An Arbor, Michigan&lt;br /&gt;41.147.113.229 Africa&lt;br /&gt;130.5.134.185 AT&amp;amp;T Bell Laboratories, Lake Mary, FL&lt;br /&gt;68.51.170.66 Comcast Cable, Savannah, GA&lt;br /&gt;&lt;br /&gt;Port 4899&lt;br /&gt;---------&lt;br /&gt;59.163.49.6 India, Bombay&lt;br /&gt;143.80.159.231 Headquarters, USAAISC, Fort Huachuca, AZ&lt;br /&gt;&lt;br /&gt;Port 25&lt;br /&gt;-------&lt;br /&gt;219.81.161.121 Taiwan&lt;br /&gt;&lt;br /&gt;Port 1433&lt;br /&gt;---------&lt;br /&gt;95.198.208.188 Sweden&lt;br /&gt;&lt;br /&gt;Port 1434&lt;br /&gt;---------&lt;br /&gt;82.178.22.22 Oman&lt;br /&gt;&lt;br /&gt;Port 2967&lt;br /&gt;---------&lt;br /&gt;69.128.111.252 WISCONSIN ENERGY CONSERVATION CORPORATION&lt;br /&gt;&lt;br /&gt;Port 5900&lt;br /&gt;---------&lt;br /&gt;85.155.70.239 Spain&lt;br /&gt;201.88.2.10 Brazil&lt;br /&gt;&lt;br /&gt;Port 5475&lt;br /&gt;---------&lt;br /&gt;87.106.15.165 Germany&lt;br /&gt;&lt;br /&gt;The IANA continues its normal activity of probing/scanning computers throughout the U.S. Internet infrastructure.&lt;br /&gt;&lt;br /&gt;The specifics on each defined IP (above) is listed below.&lt;br /&gt;&lt;br /&gt;---- Port 1026&lt;br /&gt;IP Address : 9.239.123.165 [ 9.239.123.165 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 140.200.226.166 [ 140.200.226.166 ]&lt;br /&gt;ISP : The University of Waikato&lt;br /&gt;Organization : Network Provider&lt;br /&gt;Location : NZ, New Zealand&lt;br /&gt;City : Wellington, 00 -&lt;br /&gt;Latitude : 41°30'00" South&lt;br /&gt;Longitude : 174°78'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 17.202.238.133 [ 17.202.238.133 ]&lt;br /&gt;ISP : APPLE COMPUTER&lt;br /&gt;Organization : APPLE COMPUTER&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cupertino, CA 95014&lt;br /&gt;Latitude : 37°30'42" North&lt;br /&gt;Longitude : 122°09'46" West&lt;br /&gt;&lt;br /&gt;IP Address : 17.91.7.155 [ 17.91.7.155 ]&lt;br /&gt;ISP : APPLE COMPUTER&lt;br /&gt;Organization : APPLE COMPUTER&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Cupertino, CA 95014&lt;br /&gt;Latitude : 37°30'42" North&lt;br /&gt;Longitude : 122°09'46" West&lt;br /&gt;&lt;br /&gt;IP Address : 77.34.95.139 [ 77.34.95.139 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Open Joint Stock Company Far East Telecommunicatio&lt;br /&gt;Location : RU, Russian Federation&lt;br /&gt;City : Vladivostok, 59 -&lt;br /&gt;Latitude : 43°13'33" North&lt;br /&gt;Longitude : 131°90'00" East&lt;br /&gt;&lt;br /&gt;IP Address : 190.174.3.188 [ 190-174-3-188.speedy.com.ar ]&lt;br /&gt;inetnum: 190.174/15&lt;br /&gt;status: allocated&lt;br /&gt;owner: Telefonica de Argentina&lt;br /&gt;ownerid: AR-TEAR7-LACNIC&lt;br /&gt;responsible: Agustín Gomez Dhers&lt;br /&gt;address: AV. ING. HUERGO - OBS. JUDICIALES, 723,&lt;br /&gt;address: 1065 - Buenos Aires - CF&lt;br /&gt;country: AR&lt;br /&gt;phone: +54 11 4332-2220 []&lt;br /&gt;owner-c: TEA&lt;br /&gt;tech-c: TEA&lt;br /&gt;inetrev: 190.174/15&lt;br /&gt;nserver: DNS1.MRSE.COM.AR&lt;br /&gt;nsstat: 20071015 AA&lt;br /&gt;nslastaa: 20071015&lt;br /&gt;nserver: DNS2.MRSE.COM.AR&lt;br /&gt;nsstat: 20071015 AA&lt;br /&gt;nslastaa: 20071015&lt;br /&gt;nserver: DNS3.MRSE.COM.AR&lt;br /&gt;nsstat: 20071015 AA&lt;br /&gt;nslastaa: 20071015&lt;br /&gt;nserver: DNS4.MRSE.COM.AR&lt;br /&gt;nsstat: 20071015 AA&lt;br /&gt;nslastaa: 20071015&lt;br /&gt;created: 20071005&lt;br /&gt;changed: 20071005&lt;br /&gt;&lt;br /&gt;IP Address : 97.70.91.231 [ 97.70.91.231 ]&lt;br /&gt;OrgName: bright house NETWORKS&lt;br /&gt;OrgID: BHN-2&lt;br /&gt;Address: 1219 Millennium Parkway&lt;br /&gt;City: Brandon&lt;br /&gt;StateProv: FL&lt;br /&gt;PostalCode: 33511&lt;br /&gt;Country: US&lt;br /&gt;&lt;br /&gt;IP Address :[ 152.18.12.22 ]&lt;br /&gt;ISP : University of North Carolina at Asheville&lt;br /&gt;Organization : University of North Carolina at Asheville&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Asheville, NC 28804&lt;br /&gt;Latitude : 35°64'73" North&lt;br /&gt;Longitude : 82°55'12" West&lt;br /&gt;&lt;br /&gt;IP Address : 147.93.101.5 [ 147.93.101.5 ]&lt;br /&gt;ISP : Landsbond der Christelijke Mutualiteiten&lt;br /&gt;Organization : Landsbond der Christelijke Mutualiteiten&lt;br /&gt;Location : BE, Belgium&lt;br /&gt;City : Brussel, 11 -&lt;br /&gt;Latitude : 50°83'33" North&lt;br /&gt;Longitude : 4°33'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 200.66.140.237 [ dup-200-66-140-237.prodigy.net.mx ]&lt;br /&gt;ISP : Uninet S.A. de C.V.&lt;br /&gt;Organization : Uninet S.A. de C.V.&lt;br /&gt;Location : MX, Mexico&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 23°00'00" North&lt;br /&gt;Longitude : 102°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 35.16.46.36 [ 35.16.46.36 ]&lt;br /&gt;ISP : Merit Network&lt;br /&gt;Organization : Merit Network&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Ann Arbor, MI 48104&lt;br /&gt;Latitude : 42°27'34" North&lt;br /&gt;Longitude : 83°71'33" West&lt;br /&gt;&lt;br /&gt;IP Address : 41.147.113.229 [ 41.147.113.229 ]&lt;br /&gt;organisation: ORG-AFNC1-AFRINIC&lt;br /&gt;org-name: AfriNIC - The African Network Information Centre&lt;br /&gt;org-type: RIR&lt;br /&gt;country: MU&lt;br /&gt;address: =======================================&lt;br /&gt;address: Office 03B3, 3rd Floor Cyber Tower&lt;br /&gt;address: Port Louis&lt;br /&gt;address: Mauritius&lt;br /&gt;address:&lt;br /&gt;phone: +230 466 6616&lt;br /&gt;fax-no: +230 466 6758&lt;br /&gt;remarks:&lt;br /&gt;e-mail: &lt;a href="mailto:contact@afrinic.net"&gt;contact@afrinic.net&lt;/a&gt;&lt;br /&gt;admin-c: TEAM-AFRINIC&lt;br /&gt;tech-c: TEAM-AFRINIC&lt;br /&gt;&lt;br /&gt;IP Address : 130.5.134.185 [ 130.5.134.185 ]&lt;br /&gt;ISP : AT&amp;amp;T Bell Laboratories&lt;br /&gt;Organization : AT&amp;amp;T Bell Laboratories&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Lake Mary, FL 32746&lt;br /&gt;Latitude : 28°75'78" North&lt;br /&gt;Longitude : 81°33'97" West&lt;br /&gt;&lt;br /&gt;IP Address : 68.51.170.66 [ c-68-51-170-66.hsd1.ga.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Savannah, GA -&lt;br /&gt;Latitude : 32°04'33" North&lt;br /&gt;Longitude : 81°11'67" West&lt;br /&gt;&lt;br /&gt;IP Address : 77.184.52.56 [ 77.184.52.56 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : 1&amp;amp;1 Internet AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Karlsruhe, 01 -&lt;br /&gt;Latitude : 49°00'47" North&lt;br /&gt;Longitude : 8°38'58" East&lt;br /&gt;&lt;br /&gt;---- Port 4899&lt;br /&gt;IP Address : 59.163.49.6 [ 59.163.49.6.static.vsnl.net.in ]&lt;br /&gt;ISP : Videsh Sanchar Nigam Ltd - India.&lt;br /&gt;Organization : Videsh Sanchar Nigam Ltd&lt;br /&gt;Location : IN, India&lt;br /&gt;City : Bombay, 16 -&lt;br /&gt;Latitude : 18°97'50" North&lt;br /&gt;Longitude : 72°82'58" East&lt;br /&gt;&lt;br /&gt;IP Address : 143.80.159.231 [ 143.80.159.231 ]&lt;br /&gt;ISP : Headquarters, USAAISC&lt;br /&gt;Organization : Headquarters, USAAISC&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fort Huachuca, AZ 85613&lt;br /&gt;Latitude : 31°52'73" North&lt;br /&gt;Longitude : 110°36'07" West&lt;br /&gt;&lt;br /&gt;---- Port 25&lt;br /&gt;IP Address : 219.81.161.121 [ 219-81-161-121.dynamic.tfn.net.tw ]&lt;br /&gt;ISP : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Organization : Taiwan Fixed Network CO.,LTD.&lt;br /&gt;Location : TW, Taiwan&lt;br /&gt;City : Taipei, 03 -&lt;br /&gt;Latitude : 25°03'92" North&lt;br /&gt;Longitude : 121°52'50" East&lt;br /&gt;&lt;br /&gt;---- Port 990&lt;br /&gt;IP Address : 75.126.114.34 [ vipeax.info ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : SoftLayer Technologies&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Dallas, TX 75207&lt;br /&gt;Latitude : 32°78'25" North&lt;br /&gt;Longitude : 96°82'07" West&lt;br /&gt;&lt;br /&gt;---- Port 1433&lt;br /&gt;IP Address : 195.198.208.188 [ 195-198-208-188.customer.telia.com ]&lt;br /&gt;ISP : TeliaSonera AB&lt;br /&gt;Organization : Kanal-Data AB&lt;br /&gt;Location : SE, Sweden&lt;br /&gt;City : Kungälv, 28 -&lt;br /&gt;Latitude : 57°86'67" North&lt;br /&gt;Longitude : 11°96'67" East&lt;br /&gt;&lt;br /&gt;---- Port 1434&lt;br /&gt;IP Address : 82.178.22.22 [ 82.178.22.22 ]&lt;br /&gt;ISP : Oman&lt;br /&gt;Organization : Muscat Ltd&lt;br /&gt;Location : OM, Oman&lt;br /&gt;City : Muscat, 06 -&lt;br /&gt;Latitude : 23°61'33" North&lt;br /&gt;Longitude : 58°59'33" East&lt;br /&gt;&lt;br /&gt;---- Port 2967&lt;br /&gt;IP Address : 69.128.111.252 [ &lt;a href="http://www.energyfinancesolutions.com/"&gt;http://www.energyfinancesolutions.com/&lt;/a&gt; ]&lt;br /&gt;ISP : TDS TELECOM&lt;br /&gt;Organization : WISCONSIN ENERGY CONSERVATION CORPORATION&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Janesville, WI -&lt;br /&gt;Latitude : 42°68'10" North&lt;br /&gt;Longitude : 89°04'38" West&lt;br /&gt;&lt;br /&gt;---- Port 5900&lt;br /&gt;IP Address : 85.155.70.239 [ 85.155.70.239.dyn.user.ono.com ]&lt;br /&gt;ISP : CABLETELCA, S.A.&lt;br /&gt;Organization : AUNA CANARIAS&lt;br /&gt;Location : ES, Spain&lt;br /&gt;City : Barcelona, 56 -&lt;br /&gt;Latitude : 41°38'33" North&lt;br /&gt;Longitude : 2°18'33" East&lt;br /&gt;&lt;br /&gt;IP Address : 201.88.2.10 [ 201-88-2-10.pvoce301.ipd.brasiltelecom.net.br ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Location : BR, Brazil&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 10°00'00" South&lt;br /&gt;Longitude : 55°00'00" West&lt;br /&gt;&lt;br /&gt;IP Address : 201.40.16.202 [ 201.40.16.202 ]&lt;br /&gt;ISP : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Organization : Brasil Telecom S/A - Filial Distrito Federal&lt;br /&gt;Location : BR, Brazil&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 10°00'00" South&lt;br /&gt;Longitude : 55°00'00" West&lt;br /&gt;&lt;br /&gt;---- Port 5475&lt;br /&gt;IP Address : 87.106.15.165 [ s15210777.onlinehome-server.info ]&lt;br /&gt;ISP : Schlund+Partner AG&lt;br /&gt;Organization : Schlund + Partner AG&lt;br /&gt;Location : DE, Germany&lt;br /&gt;City : Karlsruhe, 01 -&lt;br /&gt;Latitude : 49°00'47" North&lt;br /&gt;Longitude : 8°38'58" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Tuesday, October 16, 2007 (3:00 PM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We have detected and observed that Russia is now probing/attacking port 1434 with multiple "short burst" probes/attacks. As a reminder, port 1434 is primarily associated with Microsoft SQL databases.&lt;br /&gt;&lt;br /&gt;IP Address : 78.106.211.115 [ 78-106-211-115.broadband.corbina.ru ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : Investelektrosviaz Ltd.&lt;br /&gt;Location : RU, Russian Federation&lt;br /&gt;City : Moscow, 48 -&lt;br /&gt;Latitude : 55°75'22" North&lt;br /&gt;Longitude : 37°61'56" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Tuesday, October 16, 2007 (7:26 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1) We have detected and observed that China is still continuously probing/attacking all previously reported ports. The frequency of probes/attacks from China seem to have (arguably) "leveled off", however the frequency is still very short, with multiple "short burst" probes/attacks throughout the night. All China IP addresses continue to "cycle" with "short bursts" with no apparent end in sight.&lt;br /&gt;2) We have also detected and observed several new computers probing/attacking the internet. Specifically, several new computers have joined in on the probe/attack of port 1026 UDP, which has a known vulnerability for the Microsoft Messenger service.&lt;br /&gt;3) As stated in the previous BLSS Cyber Center reports, port 1026 UDP has been continuously probed/attacked by China and continues at this time, to be probed/attacked by China. The alarming news, is that computers within the United Kingdom Department Of Defense and U.S. Postal Service have now joined the probe/attack on port 1026 UDP.&lt;br /&gt;4) To further clarify the IANA listed in today's BLSS Cyber Report; The IANA probe/scan is a normal scan that routinely comes through port 1026 UDP."Also received normal probes/scans on Port 1026 UDP from the IANA", with the intent to communicate that this is normal for the IANA and not a probe/attack.&lt;br /&gt;&lt;br /&gt;Port 1026 UDP----------&lt;br /&gt;25.95.83.237 UK Ministry Of Defense&lt;br /&gt;56.38.164.130 United States Postal Service&lt;br /&gt;86.166.238.67 British Telecommunications&lt;br /&gt;51.71.178.188 United Kingdom&lt;br /&gt;24.64.72.203 Shaw Communications, Canada&lt;br /&gt;31.194.10.185 Approx somewhere in Colorado&lt;br /&gt;68.215.198.222 Bellsouth, Marietta, GA&lt;br /&gt;75.126.114.34 SoftLayer Technologies, Dallas, TX&lt;br /&gt;&lt;br /&gt;Also received normal probes/scans on port 1026 UDP from the IANA-----&lt;br /&gt;46.229.8.88 Internet Assigned Numbers Authority (IANA) - Received two scans/probes overnight&lt;br /&gt;&lt;br /&gt;Port 1027 UDP, 1028 UDP -------&lt;br /&gt;24.64.72.203 Shaw Communications, Canada&lt;br /&gt;&lt;br /&gt;Port 1024 TCP ----------------&lt;br /&gt;86.166.238.67 British Telecommunications&lt;br /&gt;&lt;br /&gt;Specific IP Data is the following:&lt;br /&gt;&lt;br /&gt;------ Port 1026 UDP --------------&lt;br /&gt;IP Address : 25.95.83.237 [ 25.95.83.237 ]&lt;br /&gt;ISP : UK Ministry of Defence&lt;br /&gt;Organization : DINSA, Ministry of Defence&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;br /&gt;&lt;br /&gt;------ Port 1026 UDP --------------&lt;br /&gt;IP Address : 56.38.164.130 [ 56.38.164.130 ]&lt;br /&gt;ISP : United States Postal Service.&lt;br /&gt;Organization : United States Postal Service.&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Raleigh, NC 27668&lt;br /&gt;Latitude : 35°79'77" North&lt;br /&gt;Longitude : 78°62'53" West&lt;br /&gt;&lt;br /&gt;------ Port 1026 UDP -------------&lt;br /&gt;IP Address 46.229.8.88&lt;br /&gt;OrgName: Internet Assigned Numbers Authority&lt;br /&gt;OrgID: IANA&lt;br /&gt;Address: 4676 Admiralty Way, Suite 330&lt;br /&gt;City: Marina del Rey&lt;br /&gt;StateProv: CA&lt;br /&gt;PostalCode: 90292-6695&lt;br /&gt;&lt;br /&gt;------- Port 1026 UDP -------------&lt;br /&gt;IP Address : 86.166.238.67 [host86-166-238-67.range86-166.btcentralplus.com ]&lt;br /&gt;ISP : British Telecommunications&lt;br /&gt;Organization : British Telecommunications&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;br /&gt;&lt;br /&gt;-------- Port 1024 TCP ------------&lt;br /&gt;IP Address : 86.166.238.67 [host86-166-238-67.range86-166.btcentralplus.com ]&lt;br /&gt;ISP : British Telecommunications&lt;br /&gt;Organization : British Telecommunications&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;br /&gt;&lt;br /&gt;--------- Port 1026, 1027, 1028 UDP -------&lt;br /&gt;IP Address : 24.64.72.203 [ 24.64.72.203 ]&lt;br /&gt;ISP : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Penhold, AB -&lt;br /&gt;Latitude : 52°13'33" North&lt;br /&gt;Longitude : 113°86'67" West&lt;br /&gt;&lt;br /&gt;--------- Port 1026 UDP --------------&lt;br /&gt;IP Address : 51.71.178.188 [ 51.71.178.188 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 54°00'00" North&lt;br /&gt;Longitude : 2°00'00" West&lt;br /&gt;&lt;br /&gt;--------- Port 1026 UDP ----------&lt;br /&gt;IP Address : 31.194.10.185 [ 31.194.10.185 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;-------- Port 1026 UDP ---------&lt;br /&gt;IP Address : 68.215.198.222 [ adsl-215-198-222.aep.bellsouth.net ]&lt;br /&gt;ISP : BellSouth.net&lt;br /&gt;Organization : BellSouth.net&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Marietta, GA -&lt;br /&gt;Latitude : 33°95'32" North&lt;br /&gt;Longitude : 84°51'77" West&lt;br /&gt;&lt;br /&gt;-------- Port 1026 UDP ---------&lt;br /&gt;IP Address : 75.126.114.34 [ vipeax.info ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : SoftLayer Technologies&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Dallas, TX 75207&lt;br /&gt;Latitude : 32°78'25" North&lt;br /&gt;Longitude : 96°82'07" West&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Sunday, October 14, 2007 (3:00 PM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1) Same previous ports that have been reported are still being scanned...&lt;br /&gt;2) China - more frequent probes/attacks on all previously defined ports, including increased frequency on port 4899 (TCP). China is now probing/attacking port 25 (TCP), which directly affects Microsoft Internet Information Services (ISS), which is the "back-bone" of a Microsoft server.&lt;br /&gt;3) We can some computer in Houston, probing port 1024 (TCP).&lt;br /&gt;4) We also have a computer, located in Herndon, VA probing/attacking port 5038 (TCP), attempting to access the Microsoft console server.&lt;br /&gt;5) South Korea (same previously reported IP), is now probing/attacking port 3128 in an attempt to find a "back door" to a firewall. To obtain more information on port 3128, use the following search parameters on search: "Microsoft port 3128 firewall" (without quotes).&lt;br /&gt;&lt;br /&gt;----- Port 4899 ------------&lt;br /&gt;IP Address : 58.215.65.237 [ 58.215.65.237 ]&lt;br /&gt;ISP : CHINANET jiangsu province network&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----- Houston Probing Port 1024 ---&lt;br /&gt;IP Address : 67.15.83.36 [ ronaldsrecordclub.com ]&lt;br /&gt;ISP : Everyones Internet&lt;br /&gt;Organization : Everyones Internet&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houston, TX 77060&lt;br /&gt;Latitude : 29°93'42" North&lt;br /&gt;Longitude : 95°40'57" West&lt;br /&gt;&lt;br /&gt;----- Herndon, VA Probing Port 5038 Attempting to access the console server -----&lt;br /&gt;IP Address : 70.62.253.83 [ rrcs-70-62-253-83.central.biz.rr.com ]&lt;br /&gt;ISP : Road Runner Business&lt;br /&gt;Organization : Road Runner Business&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, NC -&lt;br /&gt;Latitude : 35°57'64" North&lt;br /&gt;Longitude : 79°52'87" West&lt;br /&gt;&lt;br /&gt;OrgName: Road Runner HoldCo LLC&lt;br /&gt;OrgID: RCMS&lt;br /&gt;Address: 13241 Woodland Park Road&lt;br /&gt;City: Herndon&lt;br /&gt;StateProv: VA&lt;br /&gt;PostalCode: 20171&lt;br /&gt;Country: US&lt;br /&gt;&lt;br /&gt;&lt;a href="http://security-world.blogspot.com/2007_07_09_archive.html"&gt;http://security-world.blogspot.com/2007_07_09_archive.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The script works by logging into the console server on port 5038/TCP on localhost. It then issues an 'Action: Originate' command which is used to setup the bridged call.&lt;br /&gt;&lt;br /&gt;---- Direct attack on Port 25 against Internet Information Services&lt;br /&gt;(IIS) ----&lt;br /&gt;IP Address : 221.218.180.21 [ 221.218.180.21 ]&lt;br /&gt;ISP : CNCGROUP Beijing province network&lt;br /&gt;Organization : CNCGROUP Beijing Province Network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;&lt;a href="https://technet.microsoft.com/en-us/library/aa998114.aspx"&gt;https://technet.microsoft.com/en-us/library/aa998114.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;----- South Korea Probe on Port 3128 ------------&lt;br /&gt;IP Address : 218.50.1.119 [ 218.50.1.119 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : Hanaro Telecom, Inc.&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;Netherlands probing/attacking port 10000 TCP. Sans Institute reports that port 10000 TCP is vulnerable to remote code execution via "VERITAS Backup Exec Windows Agent Remote File Access Exploit (0day)"&lt;br /&gt;&lt;br /&gt;IP Address : 217.148.183.125 [ backup.vsm-hosting.nl ]&lt;br /&gt;ISP : We Dare B.V.&lt;br /&gt;Organization : We Dare B.V.&lt;br /&gt;Location : NL, Netherlands&lt;br /&gt;City : Rotterdam, 11 -&lt;br /&gt;Latitude : 51°91'67" North&lt;br /&gt;Longitude : 4°50'00" East&lt;br /&gt;&lt;br /&gt;URL:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?date=2005-08-11"&gt;http://isc.sans.org/diary.html?date=2005-08-11&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Saturday, October 13, 2007 (9:56 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1) We are observing a gradual increase in the frequency of the "short burst” probes/attacks as reported within the 12 Oct 2007 BLSS Cyber Center report.&lt;br /&gt;2) However, we have detected and are now observing two new countries with "short burst" probes/attacks on port 4899, which looks for known vulnerabilities within the Microsoft radmin server 2.0 and 2.1. The countries are Sri Lanka and Turkey:&lt;br /&gt;&lt;br /&gt;----Port 4899 ----------------------------------------------&lt;br /&gt;IP Address : 220.247.214.66 [ mail.zmvertiko.com ]&lt;br /&gt;ISP : Sri Lanka Telecom&lt;br /&gt;Organization : Z.M.Vertico Ltd&lt;br /&gt;Location : LK, Sri Lanka&lt;br /&gt;City : Padukka, 36 -&lt;br /&gt;Latitude : 6°83'25" North&lt;br /&gt;Longitude : 80°09'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 85.98.240.125 [ dsl85-98-61565.ttnet.net.tr ]&lt;br /&gt;ISP : Turk Telekom&lt;br /&gt;Organization : Turk Telekom&lt;br /&gt;Location : TR, Turkey&lt;br /&gt;City : Türk, 15 -&lt;br /&gt;Latitude : 37°05'00" North&lt;br /&gt;Longitude : 29°70'00" East&lt;br /&gt;&lt;br /&gt;The Sans Storm Center URL is below, along with posted comments from the URL:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/port.html?port=4899"&gt;http://isc.sans.org/port.html?port=4899&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As stated just above, there´s a known vulnerability related to this service (radmin).&lt;br /&gt;&lt;br /&gt;There is a known remote exploitable vulnerability in radmin server versions 2.0 and 2.1 that allows code execution.&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Friday, October 12, 2007 (10:40 AM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The past 24 hours, we have detected continuous "short burst" probes/attacks on ports 1026, 1027, 1434, 7212, 5900 and 5901, from the same previous IPs reported by BLSS. These "short burst" probes/attack, continued to "cycle on and off" our honey pot all night and continue as I write this e-mail.&lt;br /&gt;&lt;br /&gt;Additionally, we have picked up attempted probes/attacks on ports 1080, 2967, 3072 and 5110, all which have been previously reported via Sans Institute, etc., with various security warnings:&lt;br /&gt;&lt;br /&gt;Port 1080 - Attempt to gain access to proxy servers Port 2967 - Port is used by Symantec and is commonly scanned for port information Port 3072 - Attempted connection directly to port 3072 Port 5110 - Attempt to gain access to incoming mail&lt;br /&gt;&lt;br /&gt;And last but not least, we were probed again by the IANA!! :)&lt;br /&gt;&lt;br /&gt;----- Port 2967 ----------------&lt;br /&gt;IP Address : 69.248.27.110 [ c-69-248-27-110.hsd1.nj.comcast.net ]&lt;br /&gt;ISP : Comcast Cable&lt;br /&gt;Organization : Comcast Cable&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Edison, NJ -&lt;br /&gt;Latitude : 40°53'78" North&lt;br /&gt;Longitude : 74°37'14" West&lt;br /&gt;&lt;br /&gt;IP Address : 221.0.56.16 [ 221.0.56.16 ]&lt;br /&gt;ISP : CNCGROUP Shandong province network&lt;br /&gt;Organization : CNCGROUP Shandong province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Jinan, 25 -&lt;br /&gt;Latitude : 36°66'83" North&lt;br /&gt;Longitude : 116°99'72" East&lt;br /&gt;&lt;br /&gt;IP Address : 81.136.182.62 [ host81-136-182-62.in-addr.btopenworld.com ]&lt;br /&gt;ISP : British Telecommunications&lt;br /&gt;Organization : British Telecommunications&lt;br /&gt;Location : GB, United Kingdom&lt;br /&gt;City : Uxbridge, F9 -&lt;br /&gt;Latitude : 51°55'00" North&lt;br /&gt;Longitude : 0°48'34" West&lt;br /&gt;&lt;br /&gt;----- Port 3072 ------------&lt;br /&gt;IP Address : 67.15.83.36 [ ronaldsrecordclub.com ]&lt;br /&gt;ISP : Everyones Internet&lt;br /&gt;Organization : Everyones Internet&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Houston, TX 77060&lt;br /&gt;Latitude : 29°93'42" North&lt;br /&gt;Longitude : 95°40'57" West&lt;br /&gt;&lt;br /&gt;----- Port 5110 ------------&lt;br /&gt;IP Address : 69.157.156.64 [ bas6-quebec14-1167957056.dsl.bell.ca ]&lt;br /&gt;ISP : Bell Canada&lt;br /&gt;Organization : Sympatico&lt;br /&gt;Location : CA, Canada&lt;br /&gt;City : Quebec, QC -&lt;br /&gt;Latitude : 46°80'00" North&lt;br /&gt;Longitude : 71°25'00" West&lt;br /&gt;&lt;br /&gt;----- Port 1080 -------------&lt;br /&gt;IP Address : 208.77.45.13 [ 208.77.45.13 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : AKANOC Solutions&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Fremont, CA 94538&lt;br /&gt;Latitude : 37°50'79" North&lt;br /&gt;Longitude : 121°95'99" West&lt;br /&gt;&lt;br /&gt;----- Probed again by the IANA -----&lt;br /&gt;OrgName: Internet Assigned Numbers Authority&lt;br /&gt;OrgID: IANA&lt;br /&gt;Address: 4676 Admiralty Way, Suite 330&lt;br /&gt;City: Marina del Rey&lt;br /&gt;StateProv: CA&lt;br /&gt;PostalCode: 90292-6695&lt;br /&gt;Country: US&lt;br /&gt;&lt;br /&gt;Within the past hour, new probe from South Korea and a new probe from China have begun on ports 6588 and 5471 (both tcp). These parts are also well recognized as being a potential threat from numerous security web sites on the internet;&lt;br /&gt;&lt;br /&gt;----- Port 6588 TCP ------------------&lt;br /&gt;IP Address : 218.234.41.8 [ 218.234.41.8 ]&lt;br /&gt;ISP : Hanaro Telecom Co.&lt;br /&gt;Organization : SEOULMEDIA&lt;br /&gt;Location : KR, Korea, Republic of&lt;br /&gt;City : Seocho, 11 -&lt;br /&gt;Latitude : 37°48'33" North&lt;br /&gt;Longitude : 127°01'67" East&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----- Port 5471 TCP ------------------&lt;br /&gt;IP Address : 58.221.28.143 [ 58.221.28.143 ]&lt;br /&gt;ISP : CHINANET jiangsu province network&lt;br /&gt;Organization : CHINANET jiangsu province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Thursday, October 11, 2007 (5:43 PM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Within the last 20 minutes, our honey pot as detected 3 separate Chinese sites (IPs), from 3 different ISPs, probing and attacking on port 5900 TCP.&lt;br /&gt;The Sans Institute Storm Center has recognized recent attacks on this port and further documented that a probe/attack on port 5900 TCP, is because RealVNC successfully achieves unauthorized direct connections to a machine (computer).&lt;br /&gt;&lt;br /&gt;We are seeing an incredible spike with China attempting to connect directly to port 5900.&lt;br /&gt;&lt;br /&gt;--- Chinese sites (IPs) attempting an unauthorized direct TCP Connection -------&lt;br /&gt;&lt;br /&gt;IP Address : 220.185.215.36 [&lt;br /&gt;36.215.185.220.broad.tz.zj.dynamic.163data.com.cn ]&lt;br /&gt;ISP : Data Communication Division&lt;br /&gt;Organization : CHINANET-ZJ Taizhou node network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Taizhou, 04 -&lt;br /&gt;Latitude : 32°49'33" North&lt;br /&gt;Longitude : 119°90'81" East&lt;br /&gt;&lt;br /&gt;IP Address : 211.160.163.85 [ 211.160.163.85 ]&lt;br /&gt;ISP : Haidian District, Beijing&lt;br /&gt;Organization : FibrLINK Communications Co., Ltd.&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Chaoyang, 19 -&lt;br /&gt;Latitude : 41°57'03" North&lt;br /&gt;Longitude : 120°45'86" East&lt;br /&gt;&lt;br /&gt;IP Address : 124.114.94.10 [10.94.114.124.broad.xa.sn.dynamic.163data.com.cn ]&lt;br /&gt;ISP : CHINANET Shanxi(SN) province network&lt;br /&gt;Organization : CHINANET Shanxi(SN) province network&lt;br /&gt;Location : CN, China&lt;br /&gt;City : Beijing, 22 -&lt;br /&gt;Latitude : 39°92'89" North&lt;br /&gt;Longitude : 116°38'83" East&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;Black Lab Security Cyber Center Report&lt;br /&gt;Thursday, October 11, 2007 (4:29 PM CMT)&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc. (BLSS)&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Probes/Attacks on ports 7212, 1026 and 1027 continue throughout today. It appears that two more U.S. computers are participating in the probes/attacks on ports 1026 and 1027; 1) An Amateur Radio Station located somewhere&lt;br /&gt;(approximately) in Colorado (Isn't it interesting that it's an amateur radio station? I wonder if they are talking to China? -hint, hint), and 2) A computer within the DuPont industry.&lt;br /&gt;&lt;br /&gt;France has one IP that is probing/attacking port 5901 TCP. Below is a URL which documents the fact that 5901 has been probed, and the URL suggests that the probe on port 5901 could mean a new release of attack tools. Fyi, see below.&lt;br /&gt;&lt;br /&gt;----- Radio Station --------------&lt;br /&gt;IP Address : 44.229.178.141 [ 44.229.178.141 ]&lt;br /&gt;ISP : -&lt;br /&gt;Organization : -&lt;br /&gt;Location : US, United States&lt;br /&gt;City : -, - -&lt;br /&gt;Latitude : 38°00'00" North&lt;br /&gt;Longitude : 97°00'00" West&lt;br /&gt;&lt;br /&gt;OrgName: Amateur Radio Digital Communications&lt;br /&gt;OrgID: ARDC&lt;br /&gt;Address:&lt;br /&gt;City:&lt;br /&gt;StateProv:&lt;br /&gt;PostalCode:&lt;br /&gt;Country: US&lt;br /&gt;&lt;br /&gt;------ Du Pont Computer --------&lt;br /&gt;IP Address : 52.58.172.162 [ 52.58.172.162 ]&lt;br /&gt;ISP : E.I. du Pont de Nemours and Co.&lt;br /&gt;Organization : E.I. du Pont de Nemours and Co.&lt;br /&gt;Location : US, United States&lt;br /&gt;City : Wilmington, DE 19893&lt;br /&gt;Latitude : 39°56'45" North&lt;br /&gt;Longitude : 75°59'70" West&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;OrgName: E.I. du Pont de Nemours and Co., Inc.&lt;br /&gt;OrgID: EDPDNC&lt;br /&gt;Address: E.I. du Pont de Nemours and Co., Inc.&lt;br /&gt;Address: 1007 market Street&lt;br /&gt;City: Wilmington&lt;br /&gt;StateProv: DE&lt;br /&gt;PostalCode: 19893&lt;br /&gt;Country: US&lt;br /&gt;&lt;br /&gt;---- Port 5901 Probe/Attack -------------&lt;br /&gt;&lt;br /&gt;IP Address : 217.128.199.223 [&lt;br /&gt;LNeuilly-152-23-105-223.w217-128.abo.wanadoo.fr ]&lt;br /&gt;ISP : France Telecom&lt;br /&gt;Organization : France Telecom&lt;br /&gt;Location : FR, France&lt;br /&gt;City : Saint-Orens-de-Gameville, B3 -&lt;br /&gt;Latitude : 43°55'00" North&lt;br /&gt;Longitude : 1°53'33" East&lt;br /&gt;&lt;br /&gt;Port 5901 Information (url) is the following:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forums.spywareinfo.com/index.php?showtopic=101999&amp;amp;mode=linearplus"&gt;http://forums.spywareinfo.com/index.php?showtopic=101999&amp;amp;mode=linearplus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-162678064348558860?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/162678064348558860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=162678064348558860' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/162678064348558860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/162678064348558860'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/attacking-ip-addresses-and-ports-with.html' title='Attacking IP Addresses and Ports with Focus on China for Week Ending 19 Oct 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-1195787970559899177</id><published>2007-10-28T21:21:00.000-04:00</published><updated>2007-10-28T23:53:16.055-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='information assurance'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Zombie'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='probes'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='Worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><category scheme='http://www.blogger.com/atom/ns#' term='NCPH'/><title type='text'>Offshore CyberProbes/CyberAttacks: New Sophisticated Coordination</title><content type='html'>Black Lab Security Alert&lt;br /&gt;October 11, 2007&lt;br /&gt;&lt;br /&gt;Rating: Extremely Serious&lt;br /&gt;&lt;br /&gt;Black Lab Security Systems, Inc&lt;br /&gt;9250 Bendix Road, North Suite 225&lt;br /&gt;Columbia, MD 21045&lt;br /&gt;Toll Free: 888-352-1119&lt;br /&gt;Web: &lt;a title="blocked::http://www.blacklabsecurity.com/" href="http://www.blacklabsecurity.com/"&gt;http://www.blacklabsecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;a href="mailto:info@blacklabsecurity.com"&gt;info@blacklabsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Offshore CyberProbes/CyberAttacks: New Sophisticated Coordination Using&lt;br /&gt;Distributed Short-Burst Stealth (C-DSSB) Attack Techniques&lt;br /&gt;&lt;br /&gt;Upon further investigation of the recent off-shore cyber probes/attacks, Black Lab Security Systems (BLSS) has detected a new offshore attack capability consisting of sophisticated coordination utilizing short-burst attack techniques. This attack capability is even more advanced than the security industry’s recorded coordinated Distributed Denial of Service (DDoS) attacks in recent years. The objective of these C-DSSB attacks is not Denial of Service (DoS), but intrusion and code injection leading to ultimate control of the system and information extraction.&lt;br /&gt;&lt;br /&gt;In closely spaced timeframes, multiple sites from China that are consistently attempting to exploit the same inbound ports (on computer under attack) along with Chinese computers are all consistently using the same outbound port as their local port (on the attacking computer) to the United States. BLSS believes that the probes on the same ports from multiple sites within China are too consistent to be a coincidence and present a high probability of a well coordinated cyber probe/attack.&lt;br /&gt;&lt;br /&gt;A coordinating attack site (single attack IP) starts with a couple of “burst packets” of TCP or UDP. The attackers then coordinate the reminder of the Chinese and other compromised sites to hit the targeted site with “burst packets” in random order. The attackers will send attacks from site to site and then repeat. This technique hides or “stealths” the attack from looking like a standard DoS attack because COMM is broken which allows the other attacking sites to pick up where the previous attack site left off. One of the attacking IPs will continuously hang onto the attacking site for hours before taking a short break and then reconnecting.&lt;br /&gt;&lt;br /&gt;Based on the number of diverse Chinese-based attack origination locations (11 cities and 9 provinces), our intelligence believes these attacks require resources much greater than a small criminal hacking team such as Chinese hackfest champion (and suspected PLA member) Tan Dailan (aka Wicked Rose) and his Network Crack Program Hacker (NCPH) Team. NCPH was last reported working out of the Sichuan province near the Sichuan University of Science &amp;amp; Engineering. However, the NCPH’s involvement in these Window’s based cyber attacks is likely. Tan Dailan has reportedly taken a leave of absence from the University, is receiving monthly funding from an unknown source and has received PLA training. Recently, NCPH was thought to be behind a barrage of attacks against several US government agencies using 35 versions of the exploit and siphoning millions of documents back to China.&lt;br /&gt;&lt;br /&gt;One other known Chinese hacking cybercriminal: the Fujacks worm (aka as worm.whboy and Panda burning joss sticks first seen in January 2007) criminals Li Jun (age 25), Wang Lei, Zhang Shun and Lei Lei were convicted (September 2007) in a people's court in Hubei Province. The Fujacks worms were capable of: allowing others to access the computer, downloading code, remote code execution and access, modifying data, and modifying the Registry. According to Chinese media, Li Jun was sentenced to four years in prison. Wang Wanxiong, Li Jun’s lawyer, reported that Li Jun has received ten job offers for his "precious genius” including one offer from offer to become Jushu Technology’s (based in Hangzhou City, Zhejiang Province) Technology Director ($1M Chinese yuan or approximately $135,000 $US).&lt;br /&gt;&lt;br /&gt;Previous Chinese-based systematic attacks lasting for at least two years and investigated by the FBI under code named “Titan Rain” were launched from Guangdong province.&lt;br /&gt;&lt;br /&gt;Please note:&lt;br /&gt;(1) Hubei, Guangdong, and Sichuan Provinces, mentioned above, are involved in the cyber attacks profiled in this alert.&lt;br /&gt;(2) In 2003, Microsoft consented to sharing its operating systems code with the Chinese government in return for access to the Chinese market. The computer security community now fears the PLA may be putting this O/S code knowledge to use in their cyber warfare preparation efforts.&lt;br /&gt;(3) The attacks profiled in this alert required significant coordination and resources. No direct proof pointing at the top-level PLA information warfare command (Fourth Department of the PLA General Staff Headquarters) or other Chinese Government organizations has been done.&lt;br /&gt;&lt;br /&gt;Extremely Serious Rating&lt;br /&gt;BLSS defines an extremely serious rating as attacks meeting two conditions:&lt;br /&gt;(1) Continuous communications (either UDP or TCP) being received for more than 4 hours from each attacking IP address.&lt;br /&gt;(2) An attacking IP address that sent communications (TCP, UDP, or RAW), then stopped communications and restarted the communications, continuously within a 12 hour period.&lt;br /&gt;&lt;br /&gt;BACKGROUND&lt;br /&gt;(1) We are a Cyber Security Software firm.&lt;br /&gt;(2) We have established honey pot websites site on the Internet.&lt;br /&gt;(3) Using the Shadow Security Suite (our product) as the (only) security solution active on the web server/network, we have successfully detected, stopped and gathered detail forensics information profiling the cyber probes/attacks and traced the probes/attacks back to China and other locations.&lt;br /&gt;(4) We are detecting very detailed interrelated events because our packet monitor and port monitor are designed and developed using “raw sockets” methodology.&lt;br /&gt;(5) All events that take place within a Shadow protected computer are correlated in a real-time environment to determine the exact forensics while Shadow protects the computer and will not allow unauthorized modifications to execute and any remote code execution including unknown vulnerabilities (see picture below of actual China attack captured in real-time).&lt;br /&gt;&lt;br /&gt;REAL-TIME CAPTURE OF ON-GOING ATTACK&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ADDITIONAL Attack Details&lt;br /&gt;BLSS is detecting cyber probes and cyber attacks from multiple coordinated sites originating from China and other countries using similar techniques, payloads, and source transmission ports (predominately port 6000) from the attacking computer. The attacking computers located in countries outside of China as suspected to have successfully hacked by the Chinese hackers and are now remotely controlled zombie computers.&lt;br /&gt;&lt;br /&gt;The attacks will continuously cycle through these inbound ports. Ports under attack include:&lt;br /&gt;139 NetBIOS Session Service and file shares&lt;br /&gt;1026 Calendar Access Protocol port&lt;br /&gt;1027 Calendar Access Protocol port&lt;br /&gt;1434 Monitors and manages Microsoft SQL databases&lt;br /&gt;5168 Used by TrendMicro ServerProtect to receive pushed signature updates.&lt;br /&gt;7212 Unassigned. Used by GhostSurf™ open proxy and RealPlayer™.&lt;br /&gt;&lt;br /&gt;Based on our investigation, both TCP and UDP command packets are being sent to exploit ports. Therefore, BLSS believes that listed ports are categorized as a significant threat and appropriate actions should be taken within your network firewalls immediately.&lt;br /&gt;&lt;br /&gt;The cyber attacks are attempting to execute “system wide” java scripts (*.js) and other malware programs to gain overall control of the attacked computer. The Java Scripts include: RAClient.exe, RAServer.js and RAControl.js.&lt;br /&gt;&lt;br /&gt;There was no logon, no buffer over flow, nothing of any nature that would indicate capturing of the internal system name, password, etc.&lt;br /&gt;&lt;br /&gt;BLSS has been able to determine, the probes/attacks are evolving to a very advanced methodology, which no longer depends on a successful ping (ICMP), and now begins with a defined IP address, and cycles through every possible IP combination within the IP address range. As an example, a probe starts with "100.100.100.001", launches a UDP packet and/or TCP packet, then goes to "100.100.100.002", then "100.100.100.003", so forth and so on.&lt;br /&gt;&lt;br /&gt;Please note: during the "security hardening" of our honey pot website, we intentionally removed the four remote access java scripts because they are considered a security threat. You can read about these scripts as being classified as potential spyware at &lt;a href="http://www.spywared.com/files/1320/12/1"&gt;http://www.spywared.com/files/1320/12/1&lt;/a&gt;. RAClient.exe, RAServer.js and RAControl.js are listed in the middle of the page. Additionally, if you utilize a search engine, such as google.com, you will find that Chinese sites are discussing in great detail, how to use RAClient.js, RAServer.js and RAControl.js. If you will run a Google search with the following parameters "china [java script name]" (without quotes), you might be amazed at the results. If you run a google search on the specific java script file name(s), you will find many experts recommending the deletion of these specific scripts, as part of "security hardening".&lt;br /&gt;&lt;br /&gt;BLSS is using our solution (Shadow) to monitor all communications, (port activity), process activity, shell activity, and user (login activity). Essentially, we have designed a new security solution to simultaneously monitor what we feel are all the critical sub-systems within a Microsoft PC or Server. Shadow has the ability to perform an analysis on a Microsoft computer, assign a unique ID to each specific executable, including all compiled binary files and O/S scripts, (.bat, .vbs, .js, etc.), and will authenticate each executable and script before it is allowed to execute. Shadow also continuously cycles all of the internal hard drives, continuously analyzing each authorized executable (binary and O/S script) to detect an unauthorized modification to any authorized compiled binary file and O/S script. Shadow will detect an unauthorized modification without the need for the executable payload to execute. Shadow will also detect new (unauthorized) executable payloads without the requirement for the payload to execute. Shadow also places a "secure environment" around all Microsoft admin tools, CMD.EXE and PowerShell.exe, when any of these utilities are executing.&lt;br /&gt;&lt;br /&gt;IP ADDRESSES DETECTED&lt;br /&gt;The detailed information the Chinese IP addresses include:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP&lt;br /&gt;ISP&lt;br /&gt;Organization&lt;br /&gt;Location&lt;br /&gt;City&lt;br /&gt;Province&lt;br /&gt;Latitude&lt;br /&gt;Longitude&lt;br /&gt;&lt;br /&gt;125.76.238.164&lt;br /&gt;CHINANET Shanxi(SN) province network&lt;br /&gt;CHINANET Shanxi(SN) province network&lt;br /&gt;CN, China&lt;br /&gt;Beijing, 22&lt;br /&gt;Beijing&lt;br /&gt;39°92'89" North&lt;br /&gt;116°38'83" East&lt;br /&gt;&lt;br /&gt;219.148.119.2&lt;br /&gt;Data Communication Division&lt;br /&gt;CHINANET hebei province network&lt;br /&gt;CN, China&lt;br /&gt;Beijing, 22&lt;br /&gt;Beijing&lt;br /&gt;39°92'89" North&lt;br /&gt;116°38'83" East&lt;br /&gt;&lt;br /&gt;116.18.161.55&lt;br /&gt;&lt;br /&gt;ChinaNet Guangdong Province Network&lt;br /&gt;CN, China&lt;br /&gt;Guangzhou, 30&lt;br /&gt;Guangdong&lt;br /&gt;23°11'67" North&lt;br /&gt;113°25'00" East&lt;br /&gt;&lt;br /&gt;219.147.233.30&lt;br /&gt;Data Communication Division&lt;br /&gt;CHINANET HEILONGJIANG PROVINCE NETWORK&lt;br /&gt;CN, China&lt;br /&gt;Zhongshan, 07&lt;br /&gt;Guangdong&lt;br /&gt;25°53'61" North&lt;br /&gt;118°78'97" East&lt;br /&gt;&lt;br /&gt;222.216.28.161&lt;br /&gt;CHINANET Guangxi province network&lt;br /&gt;CHINANET Guangxi province network&lt;br /&gt;CN, China&lt;br /&gt;Nanning, 16&lt;br /&gt;Guangxi Zhuang&lt;br /&gt;22°81'67" North&lt;br /&gt;108°31'66" East&lt;br /&gt;&lt;br /&gt;222.217.240.248&lt;br /&gt;CHINANET Guangxi province network&lt;br /&gt;CHINANET Guangxi province network&lt;br /&gt;CN, China&lt;br /&gt;Nanning, 16&lt;br /&gt;Guangxi Zhuang&lt;br /&gt;22°81'67" North&lt;br /&gt;108°31'66" East&lt;br /&gt;&lt;br /&gt;121.18.13.107&lt;br /&gt;&lt;br /&gt;CNC Group Hebei province network&lt;br /&gt;CN, China&lt;br /&gt;Hebei, 10&lt;br /&gt;Hebei&lt;br /&gt;39°88'97" North&lt;br /&gt;115°27'50" East&lt;br /&gt;&lt;br /&gt;218.10.137.130&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.208.208.101&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.208.208.3&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;45°75'00" North&lt;br /&gt;&lt;br /&gt;221.208.208.83&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.208.208.91&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.208.208.95&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.208.208.98&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;CN, China&lt;br /&gt;Harbin, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;45°75'00" North&lt;br /&gt;126°65'00" East&lt;br /&gt;&lt;br /&gt;221.209.110.50&lt;br /&gt;CNCGROUP Heilongjiang province network&lt;br /&gt;Mudanjiang Internet Division&lt;br /&gt;CN, China&lt;br /&gt;Mudanjiang, 08&lt;br /&gt;Heilongjiang&lt;br /&gt;44°58'33" North&lt;br /&gt;129°60'00" East&lt;br /&gt;&lt;br /&gt;218.3.134.250&lt;br /&gt;Data Communication Division&lt;br /&gt;Network Center of Fast China Shipbuilding institut&lt;br /&gt;CN, China&lt;br /&gt;Zhenjiang, 04&lt;br /&gt;Jiangsu&lt;br /&gt;32°20'92" North&lt;br /&gt;119°43'42" East&lt;br /&gt;&lt;br /&gt;59.72.128.14&lt;br /&gt;China Education and Research Network&lt;br /&gt;Beihua University&lt;br /&gt;CN, China&lt;br /&gt;Jilin, 05&lt;br /&gt;Jilin&lt;br /&gt;43°85'08" North&lt;br /&gt;126°56'03" East&lt;br /&gt;&lt;br /&gt;58.247.50.243&lt;br /&gt;CNC Group ShangHai province network&lt;br /&gt;CNC Group ShangHai province network&lt;br /&gt;CN, China&lt;br /&gt;Shanghai, 23&lt;br /&gt;Shanghai&lt;br /&gt;31°00'50" North&lt;br /&gt;121°40'86" East&lt;br /&gt;&lt;br /&gt;222.215.136.52&lt;br /&gt;CHINANET Sichuan province network&lt;br /&gt;CHINANET Sichuan province network&lt;br /&gt;CN, China&lt;br /&gt;Chengdu, 32 -&lt;br /&gt;Sichuan&lt;br /&gt;30°66'67" North&lt;br /&gt;104°06'66" East&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-1195787970559899177?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/1195787970559899177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=1195787970559899177' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/1195787970559899177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/1195787970559899177'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/offshore-cyberprobescyberattacks-new.html' title='Offshore CyberProbes/CyberAttacks: New Sophisticated Coordination'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518651349466477770.post-7133197547975863680</id><published>2007-10-01T23:12:00.000-04:00</published><updated>2007-10-28T23:49:12.653-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure protection'/><category scheme='http://www.blogger.com/atom/ns#' term='titan rain'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Cyber Center Report - October 1, 2007</title><content type='html'>Black Lab Security Alert&lt;br /&gt;October 1, 2007&lt;br /&gt;&lt;br /&gt;We have had 11 extremely serious probes/attacks in the past 4 days on our "honey pot" and Shadow successfully detected and stopped all of the probes/attacks. &lt;br /&gt;&lt;br /&gt;Extremely serious is defined as two conditions;&lt;br /&gt;(1) Continuous communications (either UDP or TCP) being received for more than 4 hours from each IP address below.&lt;br /&gt;(2) An IP address that sent communications (TCP, UDP, or RAW), then stopped communications and restarted the communications, continuously within a 12 hour period.&lt;br /&gt;&lt;br /&gt;We have provided information that is very detailed information where we have successfully traced the Point-Of-Origin of the probes/attacks from China and other non-US locations&lt;br /&gt;&lt;br /&gt;BACKGROUND&lt;br /&gt;We are a Cyber Security Software firm and have been probed by offshore interests quite often since our genesis. &lt;br /&gt;We have established a honey pot site on the Internet. &lt;br /&gt;Using the Shadow Security Suite (our product) as the (only) security solution active on the web server/network, we have successfully detected and stopped the probes/attacks and traced the probes/attacks back to China and other non-US locations.&lt;br /&gt;&lt;br /&gt;DETAILS&lt;br /&gt;(1) There are seven active sites in China. The following IP connections which have met our reporting criteria and of all the connections that met our criteria, we have detected IP 121.18.13.107, using Port 139 TCP, that installed four ".js" java scripts:&lt;br /&gt;&lt;br /&gt;221.209.110.50 - CNCGROUP Heilongjiang province network -Mudanjiang&lt;br /&gt;116.18.161.55  - ChinaNet Guangdong Province Network - Guangzhou&lt;br /&gt;219.148.119.2  - Data Communication Division - Beijing&lt;br /&gt;221.208.208.3  - CNCGROUP Heilongjiang province network - Mudanjiang&lt;br /&gt;121.18.13.107  - CNC Group Hebei province network - Hebei&lt;br /&gt;125.76.238.164 - CHINANET Shanxi(SN) province network - Beijing&lt;br /&gt;218.3.134.250  - Data Communication Division, Network Center of Fast China Shipbuilding institute - Zhenjiang&lt;br /&gt;&lt;br /&gt;Of the seven sites listed above, 121.18.13.107 has attempted the most intense attack, installing Remote Access Java Scripts.  The Java Scripts include .  RAClient.exe, RAServer.js and RAControl.js. None of the seven sites above were successful against Shadow. All probes/attacks were detected and stopped.&lt;br /&gt;&lt;br /&gt;(2) There was no logon, no buffer over flow, nothing of any nature that would indicate capturing the internal system name, password, etc. All probes used Port 139 TCP.&lt;br /&gt;&lt;br /&gt;(3) Shadow has been detecting and securing our web site/network from 7 simultaneous probes/attacks from China, each from a different city in China.&lt;br /&gt;&lt;br /&gt;(4) We have been able to determine, the probes/attacks are evolving to a very advanced methodology, which no longer depends on a successful ping (ICMP), and now start with a defined IP address, and cycles through every possible IP combination within the IP address range.  As an example, a probe starts with "100.100.100.001", launches a UDP packet and/or TCP packet, then goes to "100.100.100.002", then "100.100.100.003", so forth and so on.&lt;br /&gt;&lt;br /&gt;(5) The other probes/attacks were from the following:&lt;br /&gt;&lt;br /&gt;219.240.44.147 - Hanaro Telecom Co. - South Korea - Seocho&lt;br /&gt;138.79.215.61  - CPSOFT - Australia - No City Identified&lt;br /&gt;81.188.3.50    - Easynet Belgium, Cypres - Belgium - Brussel&lt;br /&gt;24.64.132.11   - Shaw Communications - Canada - No City Identified&lt;br /&gt;&lt;br /&gt;(6) Please note: during the "security hardening" of our honey pot website, we intentionally removed the four remote access java scripts because they are considered a security threat.  You can read about these scripts as being classified as potential spyware at &lt;a href="http://www.spywared.com/files/1320/12/1"&gt;http://www.spywared.com/files/1320/12/1&lt;/a&gt;.  RAClient.exe, RAServer.js and RAControl.js are listed in the middle of the page. Additionally, if you utilize a search engine, such as google.com, you will find that Chinese sites are discussing in great detail, how to use RAClient.js, RAServer.js and RAControl.js.  If you will run a Google search with the following parameters "china [java script name]" (without quotes), you might be amazed at the results.  If you run a google search on the specific java script file name(s), you will find many experts recommending the deletion of these specific scripts, as part of "security hardening".&lt;br /&gt;&lt;br /&gt;(7) We are using our solution (Shadow) to monitor all communications, (port activity), process activity, shell activity, and user (login activity). Essentially, we have designed a new security solution to simultaneously monitor what we feel are all the critical sub-systems within a Microsoft PC or Server. Shadow has the ability to perform an analysis on a Microsoft computer, assign a unique ID to each specific executable, including all compiled binary files and O/S scripts, (.bat, .vbs, .js, etc.), and will authenticate each executable and script before it is allowed to execute.  Shadow also continuously cycles all of the internal hard drives, continuously analyzing each authorized executable (binary and O/S script) to detect an unauthorized modification to any authorized compiled binary file and O/S script.  Shadow will detect an unauthorized modification without the need for the executable payload to execute.  Shadow will also detect new (unauthorized) executable payloads without the requirement for the payload to execute. Shadow also places a "secure environment" around all Microsoft admin tools, CMD.EXE and PowerShell.exe, when any of these utilities are executing.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IMMEDIATE RECOMMENDATION&lt;br /&gt;------------------------&lt;br /&gt;&lt;br /&gt;1) Immediately block the following IP Addresses within your network firewall(s) (This is a temporary fix since these IP addresses will change on a high frequency):&lt;br /&gt;&lt;br /&gt;            121.18.13.107  &lt;-- Most Dangerous Attack&lt;br /&gt;            221.209.110.50&lt;br /&gt;            116.18.161.55&lt;br /&gt;            219.148.119.2&lt;br /&gt;            221.208.208.3&lt;br /&gt;&lt;br /&gt;2) If Shadow is not installed on a Microsoft server, turn off (disable) java scripting immediately.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP ADDRESSES DETECTED&lt;br /&gt;&lt;br /&gt;The detailed information on each IP address is below.&lt;br /&gt;&lt;br /&gt;---- China, Mudanjiang --------&lt;br /&gt;IP Address   : 221.209.110.50 [ 221.209.110.50 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : Mudanjiang Internet Division&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Mudanjiang, 08 -&lt;br /&gt;Latitude     :  44°58'33" North&lt;br /&gt;Longitude    : 129°60'00" East&lt;br /&gt;&lt;br /&gt;---- China, Guangzhou ---------&lt;br /&gt;IP Address   : 116.18.161.55 [ 116.18.161.55 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : ChinaNet Guangdong Province Network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Guangzhou, 30 -&lt;br /&gt;Latitude     :  23°11'67" North&lt;br /&gt;Longitude    : 113°25'00" East&lt;br /&gt;&lt;br /&gt;---- China, Beijing -----------&lt;br /&gt;IP Address   : 219.148.119.2 [ 219.148.119.2 ]&lt;br /&gt;ISP          : Data Communication Division&lt;br /&gt;Organization : CHINANET hebei province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Beijing, 22 -&lt;br /&gt;Latitude     :  39°92'89" North&lt;br /&gt;Longitude    : 116°38'83" East&lt;br /&gt;&lt;br /&gt;----- China, Harbin -----------&lt;br /&gt;IP Address   : 221.208.208.3 [ 221.208.208.3 ]&lt;br /&gt;ISP          : CNCGROUP Heilongjiang province network&lt;br /&gt;Organization : CNCGROUP Heilongjiang province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Harbin, 08 -&lt;br /&gt;Latitude     :  45°75'00" North&lt;br /&gt;Longitude    : 126°65'00" East&lt;br /&gt;&lt;br /&gt;-----  China, Hebei -----------&lt;br /&gt;IP Address   : 121.18.13.107 [ 121.18.13.107 ]&lt;br /&gt;ISP          : -&lt;br /&gt;Organization : CNC Group Hebei province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Hebei, 10 -&lt;br /&gt;Latitude     :  39°88'97" North&lt;br /&gt;Longitude    : 115°27'50" East&lt;br /&gt;&lt;br /&gt;----- China Beijing -------------------&lt;br /&gt;IP Address   : 125.76.238.164 [ 125.76.238.164 ]&lt;br /&gt;ISP          : CHINANET Shanxi(SN) province network&lt;br /&gt;Organization : CHINANET Shanxi(SN) province network&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Beijing, 22 -&lt;br /&gt;Latitude     :  39°92'89" North&lt;br /&gt;Longitude    : 116°38'83" East&lt;br /&gt;&lt;br /&gt;---- China, Zhenjiang ------------------------&lt;br /&gt;IP Address   : 218.3.134.250 [ 218.3.134.250 ]&lt;br /&gt;ISP          : Data Communication Division&lt;br /&gt;Organization : Network Center of Fast China Shipbuilding institut&lt;br /&gt;Location     :  CN, China&lt;br /&gt;City         : Zhenjiang, 04 -&lt;br /&gt;Latitude     :  32°20'92" North&lt;br /&gt;Longitude    : 119°43'42" East&lt;br /&gt;&lt;br /&gt;----- Korea, Seocho -----------&lt;br /&gt;IP Address   : 219.240.44.147 [ 219.240.44.147 ]&lt;br /&gt;ISP          : Hanaro Telecom Co.&lt;br /&gt;Organization : Ilifezone&lt;br /&gt;Location     :  KR, Korea, Republic of&lt;br /&gt;City         : Seocho, 11 -&lt;br /&gt;Latitude     :  37°48'33" North&lt;br /&gt;Longitude    : 127°01'67" East&lt;br /&gt;&lt;br /&gt;------ Australia ------------&lt;br /&gt;IP Address   : 138.79.215.61 [ 138.79.215.61 ]&lt;br /&gt;ISP          : CPSOFT&lt;br /&gt;Organization : CPSOFT&lt;br /&gt;Location     :  AU, Australia&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  27°00'00" South&lt;br /&gt;Longitude    : 133°00'00" East&lt;br /&gt;&lt;br /&gt;----- Belgium Brussels ---------------&lt;br /&gt;IP Address   : 81.188.3.50 [ 81-188-3-50.sdsl.easynet.be ]&lt;br /&gt;ISP          : Easynet Belgium&lt;br /&gt;Organization : Cypres&lt;br /&gt;Location     :  BE, Belgium&lt;br /&gt;City         : Brussel, 11 -&lt;br /&gt;Latitude     :  50°83'33" North&lt;br /&gt;Longitude    :   4°33'33" East&lt;br /&gt;&lt;br /&gt;----- Canada -------------------------&lt;br /&gt;IP Address   : 24.64.132.11 [ S010600095b0f1aa1.lb.shawcable.net ]&lt;br /&gt;ISP          : Shaw Communications&lt;br /&gt;Organization : Shaw Communications&lt;br /&gt;Location     :  CA, Canada&lt;br /&gt;City         : -, - -&lt;br /&gt;Latitude     :  60°00'00" North&lt;br /&gt;Longitude    :  95°00'00" West&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518651349466477770-7133197547975863680?l=cybersecurityblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityblog.blogspot.com/feeds/7133197547975863680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518651349466477770&amp;postID=7133197547975863680' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7133197547975863680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518651349466477770/posts/default/7133197547975863680'/><link rel='alternate' type='text/html' href='http://cybersecurityblog.blogspot.com/2007/10/cyber-center-report-october-1-2007.html' title='Cyber Center Report - October 1, 2007'/><author><name>Cyber Security BLOG</name><uri>http://www.blogger.com/profile/01478331283994226607</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
