Leger Research Fondation

Fondation de recherche Léger

May 2008

Are you being hacked: Results of one week of home HoneyPot data.

 

In early April, I installed a HoneyPot on my home network for a period of one week. My home network is connected to the Internet using the Cable Modem service provided by Videotron, a large ISP in Quebec. I was quite surprized to note that I had 12079 attempts to connect or send attacks to my home computer network. A summary of my results are provided in the following table.
 

Date

Number of attempts

Sunday March 9th

5221

Monday March 10th

989

Tuesday March 11th

1080

Wednesday March 12th

1144

Thursday March 13th

1580

Friday March 14th

963

Saturday March 15th

1102

Total:

12079

Table 1: summary of the results

What is a honeyPot ?

A honeypot, a name inspired from Winnie the Poo, is a device that can be installed on a network to catch intruders. Purposely made to be enticing to an intruder or computer system cracker, it give the impression that multiple TCP-IP ports are open on computers that can be reached through a network, in this case the Internet. Honeypots have basic intrusion detection capabilities built into them in order to collect information on the intrusion attempts. It can be viewed as a form of entrapment. The Open Source product I used to perform this test is HoneyBot, from Atomic Software Solutions (http://www.atomicsoftwaresolutions.com/ ). Please note that I have no connection to this company and found the product by doing a Google search.

So who is attacking me ?

Interestly, most trafic was attemps to display Windows messages on my computer via ports 1026, 1027 and 1028. These messages where intended at having me purchase a Registry Cleaning software. A simple Google search indicates that this may be a form of Internet Scam. There where also many attempts o connect to TCP-IP port 21, the port used by FTP servers. Other ports frequently accessed where ports 22, 1434, 2967, 5900, 8000 and 8555.

By doing a Whois on the source IP address, I was able to find out that a large portion of the packets appeared to come from within Canada, through addresses allocated to Shaw Communications and COGECO. Most likely, based on my personal experience, I would suspect thay originate from compromised computers acting as relays, also called zombies. However, I identified a large number of attempts from China, South Korea and Iran. Attempts where made from France, USA, China and Iran. Individual is Iran and China made several attempts to connect to port 21 (FTP) on my Honeypot.

Should you be concerned ?

I think this should deeply concern all legitimate users of the Internet, I know I am. This is potentially a big problem, which I reported to the Royal Canadian Mounted Police (RCMP), via their online fraud reporting service. They have not responded. As well, I complained to my ISP, Videotron, who has not responded to my email.

The following table provides a sample of some of the offending IP addresses.
 

Source IP

Location

118.236.131.108

Tokyo Japan

125.65.109.49

Mianyang Sichuan PR China

125.65.112.152

Chengdu SiChuan PR China

143.178.92.210

Amsterdam, NL

147.53.21.30

Notre-Dame Illinois USA

152.17.181.134

Winston-Salem, NC, USA

158.97.90.64

Mexico

16.72.136.23

HP, Palo-Alto, CA, USA

17.212.77.244

Apple, Cupertino, CA, USA

189.67.195.13

Brazil

192.222.80.199

DoD Columbus OH USA

194.54.33.33

Ankara, Turkey

201.229.38.165

Aruba

202.101.235.100

Jiangxi, China

202.28.79.167

Bangkok, Thailand

202.97.238.194

Heilongjiang, China

202.99.11.99

Neijing, China

203.197.237.145

Mumbai, India

204.143.34.175

Centennial, CO, USA

205.78.116.65

US NAVY, Pensacola, FL, USA

211.232.192.220

Jeonju, South Korea

218.10.137.141

Heilongjiang, China

218.206.140.236

jiangsu, China

220.191.233.133

Taizhou Electronic Government Network, China

220.227.158.83

Mumbai, India

221.208.208.99

Beijing, China

221.209.110.20

Heilongjiang, China

24.64.100.67

Calgary, Alberta

57.103.68.198

Neuilly, 92 , France

58.20.15.126

Hunan, China

58.20.15.126

Hunan, China

58.236.26.54

Seoul, South Korea

59.63.157.211

NANCHANG,JIANGXI, China

60.190.163.66

Huzhou,Zhejiang, China

60.190.163.66

Huzhou,Zhejiang, China

60.191.43.40

Hangzhou,Zhejiang, China

61.132.223.14

Anhui, China

61.159.245.166

Yunnan, China

62.193.246.160

Paris, France

64.59.69.151

Southfield, MI, USA

74.138.15.28

Louisville, KY, USA

74.210.128.33

Trois-rivières, QC

Table 2: IP address and WHOIS
  info@leger.ca
©MarcAndreLéger, 05.04.2008 10:41:02 -0400