Sagonet - Failing miserably with network security Someone needs to handle this.
DLasher at newedgenetworks.com
Mon Oct 30 16:54:23 UTC 2006
Not that this is his real name, or business, but a whois on the IP
Sago Networks SAGO-20030401 (NET-65-110-32-0-1)
126.96.36.199 - 188.8.131.52
Anton Tenev SAGO-65-110-62-120 (NET-65-110-62-120-1)
184.108.40.206 - 220.127.116.11
From: owner-nanog at merit.edu [mailto:owner-nanog at merit.edu] On Behalf Of
Sent: Sunday, October 29, 2006 11:29 AM
To: nanog at nanog.org
Cc: abuse at sagonet.com
Subject: Sagonet - Failing miserably with network security Someone needs
to handle this.
We have a serious hacker here who is ACTIVLY engaged in logins on our
network (have him in a honeypot at the moment). He is running exploits
from your network and also I have been hearing from others that you have
been notified of this a few times yet have done nothing about it. Can
we get someone to handle this immediately please?
This hacker has rooted at least 35 servers on a friends network
competitor) and now hes scanning ours...
This is what was said by my friend after contacting you guys about this:
"Good... They will not listen... I have provided them logs, screen
Additionally, I would LOVE to know what is on that server... this guy is
not to be taken lightly, he is VERY methodical and patient. He's
problably owning your network too.
[root at mail /home]# netstat -an
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address
tcp 0 0 0.0.0.0:21 0.0.0.0:*
tcp 0 0 :::38300 :::*
tcp 0 0 ::ffff:18.104.22.168:38300
More information about the NANOG