At 08:44 PM 12/1/2009, Brett Glass wrote:
At 12:09 PM 12/1/2009, Mike Tancsa wrote:

http://isc.sans.org/trends.html
and
http://isc.sans.org/port.html

Do not seem to show any increase.

Do those stats account for the fact that the attackers may first be fingerprinting servers to see if they're running FreeBSD?

No idea. But looking at the logs of various hosts targeted by distributed scanners that hit my network, they dont seem to be that intelligent. There is no reason it couldnt be done, but I havent seen it yet here anyways.

        ---Mike


--Brett

--------------------------------------------------------------------
Mike Tancsa,                                      tel +1 519 651 3400
Sentex Communications,                            [email protected]
Providing Internet since 1994                    www.sentex.net
Cambridge, Ontario Canada                         www.sentex.net/mike

_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"

Reply via email to