> I have seen this a number of times from various IP addresses and it is
> always exactly the same. Our product which detected this prevents against
> these types of attacks anyway so it is not a problem but I was wondering if
> it is a particular attack tool going round the Internet profiling different
> sites to see how many connections they support.
Out of curiosity to possibly reclarify your definition of an attack...
What type of attacks do these more than 3 connections fall into?
-Daniel Uriah Clemens
Esse quam videra
(to be, rather than to appear)
http://www.birmingham-infragard.org | 2053284200
fingerprint: EDF0 6566 2A4A 220E 5760 EA1F 0424 6DF6 F662 F5BD
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html