Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Incident Responsearrow What are these stealth mode connection attempts and should I be concerned?
EH-Net
May 25, 2013, 11:27:22 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What are these stealth mode connection attempts and should I be concerned?  (Read 8746 times)
0 Members and 1 Guest are viewing this topic.
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« on: December 31, 2010, 07:34:30 AM »

Apologies if this is the wrong forum to post this, it's my best guess.

I've setup my ipfw firewall on Mac Snow Leopard.  In checking my console logs, I continually get this message:

Stealth mode connection attempt to UDP 10.8.4.14:(port) from ip address

The ip addresses are almost always the following ones
178.47.171.97
216.131.95.20
71.146.211.156
128.194.77.181
87.221.235.25
70.109.191.180
72.23.181.106
174.103.147.143
217.149.5.169
209.59.255.39
210.242.195.50

I looked up these addresses with http://whois.domaintools.com/

Some interesting results:
178.47.171.97 Russian Federation Ojsc Uralsvyazinfor

216.131.95.20 United States South Lake Tahoe Reliablehosting.com - Network Services
(Interesting message afterwards)
Reverse IP:
1 website uses this address. (example: uktranssexual.com)

71.146.211.156 United States Sarah

128.194.77.181 United States College Station Texas A&m University

87.221.235.25 Spain Barcelona Jazztel Triple Play Services

70.109.191.180 United States South Londonderry Fairpoint Communications I

72.23.181.106 United States Meadville Armstrong Cable Service

174.103.147.143 United States Milford Road Runner Holdco Ll

217.149.5.169 Spain Filnet Serveis I Comunicacions

209.59.255.39 United States Charlotte Carolina Internet Ltd

210.242.195.50 Taiwan Taipei Nextlink Ltd

There are more but I guess it's not worth posting?

What's most interesting is 216.131.95.20.  There are many repeat occurrences of this.  Almost all repeat at some point in the log, but this one in particular is quite often.

What are these connection attempts and should I be concerned?
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #1 on: December 31, 2010, 07:52:40 AM »

I've also notice din my Little Snitch app firewall it reports this:

mDNSResponder connection to ns1.california.net
Which resolves to 216.131.95.20

A Google search for
"ns1.california.net" mDNSResponder
returns zero results.

What's going on?  Can anybody help?
« Last Edit: December 31, 2010, 07:54:38 AM by macattack » Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #2 on: December 31, 2010, 08:10:11 AM »

Not only that, but every time I click refresh page it shows it's connecting to ns1.california.net
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #3 on: December 31, 2010, 10:13:10 AM »

Sounds to me like ns1.california.net is a nameserver, and you're seeing DNS resolution for whatever is browsing and needs to resolve names to ip addressess.  Very likely normal traffic, there.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #4 on: January 01, 2011, 04:15:30 AM »

Thanks for the help.  It seems ok...but, what is this:

216.131.95.20 United States South Lake Tahoe Reliablehosting.com - Network Services
(Interesting message afterwards)
Reverse IP:
1 website uses this address. (example: uktranssexual.com)

Why does it say "1 website uses this address.."

Putting in this address in google turns up a LOT of porn sites:
ns1.california.net

Can I block this site, will it cause problems?
Or better yet, is there a way to make sure it's resolving names as opposed to accessing servers for a malicious intent?
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #5 on: January 01, 2011, 04:19:11 AM »

Also, why does it say "steal mode connection attempt?"

The fact that my internet accesses this IP and and has stealth mode attempts is very disturbing.
Logged
macattack
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #6 on: January 01, 2011, 04:23:46 AM »

Apologies...turns out it's the nameserver for my VPN service.

=)

Thanks again for your help (I'm still learning).
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #7 on: January 01, 2011, 09:22:05 AM »

No worries, macattack.  That's what we're all here for - knowledge share and learning.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.