Politie poortscans?
17-05-2003,18:11 door
Ik krijg hier op ons serverpark meldingen binnen van poortscans met source IP smurf.politie.nl.. zowel tcp als udp.. meer mensen dit tegen gekomen? Wellicht een spoof?
Interesting ports on smurf.politie.nl (194.151.195.222):
(The 1621 ports scanned but not shown below are in state: filtered)
Port State Service
25/tcp open smtp
53/tcp open domain
No exact OS matches for host (test conditions non-ideal).
Uptime 4.674 days (since Tue May 13 17:53:35 2003)
~# telnet smurf.politie.nl 25
Trying 194.151.195.222...
Connected to smurf.politie.nl.
Escape character is '^]'.
220 internetfw.politie.nl ESMTP service
~# dig politie.nl mx
; <<>> DiG 8.3 <<>> politie.nl mx
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;; politie.nl, type = MX, class = IN
;; ANSWER SECTION:
politie.nl. 59m53s IN MX 100 mailbackup1.kpn.net.
politie.nl. 59m53s IN MX 10 smurf.politie.nl.
;; AUTHORITY SECTION:
politie.nl. 59m53s IN NS smurf.politie.nl.
politie.nl. 59m53s IN NS ns2.kpn.net.
;; ADDITIONAL SECTION:
smurf.politie.nl. 35M IN A 194.151.195.222
mailbackup1.kpn.net. 19h33m20s IN A 194.151.226.36
~# dig politie.nl ns
; <<>> DiG 8.3 <<>> politie.nl ns
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
;; QUERY SECTION:
;; politie.nl, type = NS, class = IN
;; ANSWER SECTION:
politie.nl. 59m8s IN NS ns2.kpn.net.
politie.nl. 59m8s IN NS smurf.politie.nl.
;; ADDITIONAL SECTION:
smurf.politie.nl. 34m15s IN A 194.151.195.222
Domain name:
politie.nl (first domain)
Status: active
Registrant:
Nederlands Politie Instituut
Nassaulaan 9 10
2514 JS 'S-GRAVENHAGE
Netherlands
Domicile:
N/A
Committed to ADR: no
Administrative contact:
M. Zeevenhooven-Sanders
+31 70 3180276
[email]postmaster@politie.nl[/email]
Registrar:
KPN Telecom B.V. Operator Vaste Net
Regulusweg 1
2516 AC 'S-GRAVENHAGE
Netherlands
Technical contact:
Domain Off IO DO Levering
+31 70 4512555
[email]domain@kpn.net[/email]
Domain nameservers:
smurf.politie.nl 194.151.195.222
ns2.kpn.net 194.151.228.50
Date first registered: 27-12-1996
Record last updated: 04-04-2001
Record maintained by: NL Domain Registry