> Sep 30 05:53:38 www portsentry[386]: attackalert: Host: 217.72.160.65 is
already blocked. Ignoring
> Sep 30 05:53:42 www portsentry[386]: attackalert: Connect from host:
217.72.160.65/217.72.160.65 to UDP port: 69
Port 69 is TFTP (trivial file transfer protocol) which is used by one of the
latest windows worms. Its attempting to spread itself, and as it scans
random IPs there really isn't any thought behind scanning your RAQs.
It poses no threat to your servers, but sustained scanning could easily
begin to eat into your bandwidth.

Mark Anderson.



_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security

Reply via email to