<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is that a hack? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625669#M1036861</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ip address 196.12.53.52 attempted to access to your firewall using SSH&lt;/P&gt;&lt;P&gt;Its nothing serious and quite often.. Intruders are using automated scripts to try find open ssh, telnet ports  on public IPs if ports are open they can use dictionary/brute-force  attack to gain unauthorized access &lt;/P&gt;&lt;P&gt;Its reason why is highly recommend limit access for administration services (telnet, ssh , rdp .....) and use strong passwords&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Jan 2007 10:28:44 GMT</pubDate>
    <dc:creator>m.sir</dc:creator>
    <dc:date>2007-01-15T10:28:44Z</dc:date>
    <item>
      <title>Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625668#M1036847</link>
      <description>&lt;P&gt;Hi Forum,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get a lot of messages like :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 15 2007 17:02:16: %ASA-3-710003: TCP access denied by ACL from 196.12.53.52/39367 to outside:29.91.35.9/22 where 29.91.35.9 is my outside address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could that indicate someone is trying to access from outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;paul&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625668#M1036847</guid>
      <dc:creator>paulnigel</dc:creator>
      <dc:date>2019-03-11T09:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625669#M1036861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ip address 196.12.53.52 attempted to access to your firewall using SSH&lt;/P&gt;&lt;P&gt;Its nothing serious and quite often.. Intruders are using automated scripts to try find open ssh, telnet ports  on public IPs if ports are open they can use dictionary/brute-force  attack to gain unauthorized access &lt;/P&gt;&lt;P&gt;Its reason why is highly recommend limit access for administration services (telnet, ssh , rdp .....) and use strong passwords&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 10:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625669#M1036861</guid>
      <dc:creator>m.sir</dc:creator>
      <dc:date>2007-01-15T10:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625670#M1036865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you m.sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I see some unknown telnet outside command from unknown addresses in my ASA firwall, does it mean that my ASA firewall was hacked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one ASA firewall for internet access, should I put another firewall inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 00:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625670#M1036865</guid>
      <dc:creator>paulnigel</dc:creator>
      <dc:date>2007-01-16T00:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625671#M1036870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is really not hacked.. there can be lots of messages like this on the firewalls, because the outside interface is on the public segment, which is exposed to the internet !!!! people can do a lot of port scan/ IP scan etc. The firewall will anyway block this and will not let you inside your network.. that is why a firewall is in existance !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you still want to prevent important protocols like ssh, telnet, snmp etc not hitting ur firewall, you can block them on the outside router's WAN or LAn interface.. you can also ask the ISP to apply security access-lists at their end.. you can ask them to block all unnecessary ports like SSH, telnet, SNMP, NTP etc, which are vulnerable. You can just open ports which are needed, like 80, 443, 21 etc !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. all the best..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 00:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625671#M1036870</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-16T00:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625672#M1036873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this really help. and it tell me how weak I am in firewalling. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much,&lt;/P&gt;&lt;P&gt;py&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 02:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625672#M1036873</guid>
      <dc:creator>paulnigel</dc:creator>
      <dc:date>2007-01-16T02:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625673#M1036875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats cool paul. let us know if you need anything else. or else mark the case as solved which can help others, searching for an answer in this forum. rate replies if found useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 13:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625673#M1036875</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-16T13:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625674#M1036877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A good place to start for firewalls:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/ps6120/index.html" target="_blank"&gt;http://cisco.com/en/US/products/ps6120/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html" target="_blank"&gt;http://cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if this helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 13:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625674#M1036877</guid>
      <dc:creator>5220</dc:creator>
      <dc:date>2007-01-16T13:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625675#M1036880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would be very concerned if you see the commands in your config like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet some_hacker_IP net &lt;NETMASK&gt; outside&lt;/NETMASK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because this would require access to the cli.  They can only use this of course, after establishing ipsec first unlike ssh which can be used directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 22:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625675#M1036880</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2007-01-16T22:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is that a hack?</title>
      <link>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625676#M1036882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mmomrris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, i see this command inside my ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet some_hacker_IP net &lt;NETMASK&gt; outside &lt;/NETMASK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did setup remote vpn and site to site vpn on the ASA, besides, i have 2 GRE tunnels, one from a router and the other one from the core switch linking to remote sites. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it because my vpn setup is insecure? this really worry me. What kind of info do you need to understand the causes of this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much,&lt;/P&gt;&lt;P&gt;py&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2007 01:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-that-a-hack/m-p/625676#M1036882</guid>
      <dc:creator>paulnigel</dc:creator>
      <dc:date>2007-01-17T01:32:41Z</dc:date>
    </item>
  </channel>
</rss>

