Anyone seen this before?

Sunday evening our network was scanned (hardly unusual, of course, *sigh*),
but with a twist.  It was a *distributed* scan, from four different hosts,
coordinated so that each host scanned a unique subset of IP addresses.  All
happening at the same time.

I'm not sure what the point is, other than, perhaps, making it harder to
automate detection of scans...

At first I thought I was looking at a dDoS, but other than the odd
sourcing, it was just an ordinary FTP port scan.

-Robert


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to