Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 71 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Incident Responsearrow What are these stealth mode connection attempts and should I be concerned?
EH-Net
May 26, 2012, 02:29:57 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What are these stealth mode connection attempts and should I be concerned?  (Read 5266 times)
0 Members and 1 Guest are viewing this topic.
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« on: December 31, 2010, 07:34:30 AM »

Apologies if this is the wrong forum to post this, it's my best guess.

I've setup my ipfw firewall on Mac Snow Leopard.  In checking my console logs, I continually get this message:

Stealth mode connection attempt to UDP 10.8.4.14:(port) from ip address

The ip addresses are almost always the following ones
178.47.171.97
216.131.95.20
71.146.211.156
128.194.77.181
87.221.235.25
70.109.191.180
72.23.181.106
174.103.147.143
217.149.5.169
209.59.255.39
210.242.195.50

I looked up these addresses with http://whois.domaintools.com/

Some interesting results:
178.47.171.97 Russian Federation Ojsc Uralsvyazinfor

216.131.95.20 United States South Lake Tahoe Reliablehosting.com - Network Services
(Interesting message afterwards)
Reverse IP:
1 website uses this address. (example: uktranssexual.com)

71.146.211.156 United States Sarah

128.194.77.181 United States College Station Texas A&m University

87.221.235.25 Spain Barcelona Jazztel Triple Play Services

70.109.191.180 United States South Londonderry Fairpoint Communications I

72.23.181.106 United States Meadville Armstrong Cable Service

174.103.147.143 United States Milford Road Runner Holdco Ll

217.149.5.169 Spain Filnet Serveis I Comunicacions

209.59.255.39 United States Charlotte Carolina Internet Ltd

210.242.195.50 Taiwan Taipei Nextlink Ltd

There are more but I guess it's not worth posting?

What's most interesting is 216.131.95.20.  There are many repeat occurrences of this.  Almost all repeat at some point in the log, but this one in particular is quite often.

What are these connection attempts and should I be concerned?
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #1 on: December 31, 2010, 07:52:40 AM »

I've also notice din my Little Snitch app firewall it reports this:

mDNSResponder connection to ns1.california.net
Which resolves to 216.131.95.20

A Google search for
"ns1.california.net" mDNSResponder
returns zero results.

What's going on?  Can anybody help?
« Last Edit: December 31, 2010, 07:54:38 AM by macattack » Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #2 on: December 31, 2010, 08:10:11 AM »

Not only that, but every time I click refresh page it shows it's connecting to ns1.california.net
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #3 on: December 31, 2010, 10:13:10 AM »

Sounds to me like ns1.california.net is a nameserver, and you're seeing DNS resolution for whatever is browsing and needs to resolve names to ip addressess.  Very likely normal traffic, there.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #4 on: January 01, 2011, 04:15:30 AM »

Thanks for the help.  It seems ok...but, what is this:

216.131.95.20 United States South Lake Tahoe Reliablehosting.com - Network Services
(Interesting message afterwards)
Reverse IP:
1 website uses this address. (example: uktranssexual.com)

Why does it say "1 website uses this address.."

Putting in this address in google turns up a LOT of porn sites:
ns1.california.net

Can I block this site, will it cause problems?
Or better yet, is there a way to make sure it's resolving names as opposed to accessing servers for a malicious intent?
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #5 on: January 01, 2011, 04:19:11 AM »

Also, why does it say "steal mode connection attempt?"

The fact that my internet accesses this IP and and has stealth mode attempts is very disturbing.
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #6 on: January 01, 2011, 04:23:46 AM »

Apologies...turns out it's the nameserver for my VPN service.

=)

Thanks again for your help (I'm still learning).
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #7 on: January 01, 2011, 09:22:05 AM »

No worries, macattack.  That's what we're all here for - knowledge share and learning.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.172 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.