Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: DOD Inside

Subject: Re: DOD Inside
Date: 8 Apr 2006 02:18:40 -0000
I'm very new to this so please be gentle!

Having read about the DoD IP issues in here, I thought I might add my £0.02:

My router logs from the 28-03-2006 show a very strange sequence of port 
attempts.

Tue, 2006-03-28 05:20:52 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1035 - [DOS]
Tue, 2006-03-28 11:22:41 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1033 - [DOS]
Tue, 2006-03-28 11:22:41 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1035 - [DOS]
Tue, 2006-03-28 17:25:53 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1033 - [DOS]
Tue, 2006-03-28 21:56:20 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1034 - [DOS]
Tue, 2006-03-28 21:56:20 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1035 - [DOS]
Tue, 2006-03-28 23:28:43 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1035 - [DOS]
Tue, 2006-03-28 23:28:43 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1027 - [DOS]
Wed, 2006-03-29 09:58:11 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1035 - [DOS]
Wed, 2006-03-29 11:30:32 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,139 - [DOS]
Wed, 2006-03-29 11:30:32 - UDP Packet - Source:7.12.12.16,13364 
Destination:xx.xx.xx.xx,1031 - [DOS]

Having checked out the source IP address I got:

OrgName:    DoD Network Information Center 
OrgID:      DNIC
Address:    3990 E. Broad Street
City:       Columbus
StateProv:  OH
PostalCode: 43218
Country:    US

NetRange:   7.0.0.0 - 7.255.255.255 
CIDR:       7.0.0.0/8 
NetName:    DISANET7
NetHandle:  NET-7-0-0-0-1
Parent:     
NetType:    Direct Allocation
Comment:    Defense Information Systems Agency
Comment:    DISA /D3
Comment:    11440 Isaac Newton Square
Comment:    Reston, VA 22090-5087 US
RegDate:    1997-11-24
Updated:    1998-09-26

Obviously this is not correct, but strange that the source IP should be 
masquerading as a DoD IP.

<Prev in Thread] Current Thread [Next in Thread>