I was collecting data for my thesis, blissfully unaware.

On the initial analysis I didn't notice anything. Only when I was refining some parameters for the second time did I spot flows with flags A (ACK) and R (RESET). > SCAN! I stopped what I was doing and looked only at flows with the S (SYN) flag — and I couldn't believe my eyes.

Not one, not two... but nineteen scanners. Their wishes were varied. Starting with SSH (TCP/22), SMTP (TCP/25), RPC (TCP/135), SAMBA (TCP/445), MYSQL (TCP/1433), RDP (TCP/3389), VNC (TCP/5900), HTTP (TCP/8080), and a curious port TCP/54045. My machine responded .A.R.. (port closed) and that was that. The list of visitors (in order of visit time): - Georgia, Tbilisi - India, Ghaziabad - Romania - China, Nanjing, CHINANET - Vietnam, Ho Chi Minh City - India, Latur - Indonesia, Jakarta - United Kingdom - United States, Danvers - Hong Kong - United States, Ashburn - Canada, Kelowna - British Indian Ocean Territory - Bulgaria, Sliven - Czech Republic, Šumperk - China, Xuzhou, CHINANET - Mexico, Mexico - Czech Republic, Jablonec nad Nisou - Brazil, Marília

Other Related Posts:

Internet Security Talk

In my hometown

Just as the internet changes every day, online security has to keep up. Below you'll find a few links to useful resources on internet security and privacy.

Current security news

The Security Roundup series, published every Monday on Root

News from the national team CSIRT.CZ...

1st Feb 2020