We are currently seeing in our firewall logs excessive ICMP type 8 request followed by probes on TCP port 135 coming from multiple sites throughout the internet. Early this caused a DOS on our ISP's router ahead of our firewall.
Jon Dolinar Network Security Supervisor Cuyahoga Community College [EMAIL PROTECTED] 216.987.4354 -----Original Message----- From: Abraham, Antony (Cognizant) [mailto:[EMAIL PROTECTED] Sent: Monday, August 18, 2003 10:18 AM To: [EMAIL PROTECTED]; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: RE: [Full-Disclosure] [UPDATE] ping floods Hi, We do have the same problem. Incidents.org has recorded the same (http://isc.incidents.org/) but not much detail available. Thanks, Antony Abraham -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Monday, August 18, 2003 6:59 PM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: [Full-Disclosure] [UPDATE] ping floods Frank, Yes, exactly, our ICMP requests are also detected as Cyber kit 2.2 Seems we share the same problem. Some others too? Brgrds _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
