Hello:

After changing my ISP service from ISDN to a T1 line, I see a lot more
'poking around' activity.

On my logfile, I see a series of attempts to connect to inactive IP
addresses and ports(80,25,21) every 3-5 seconds for about 30 minutes.  This
is repeated for different IP addresses assigned to us but not yet in
service.  I suspect this happens also for legit addresses/ports but Gnatbox
does not log them as my filters are set for 'nolog'.

This pattern happens several times during the day/night.  Connecting IP
addresses are usually untraceable.

Are these 'script kiddies' out there flexing their wings or just my
imagination?

I am glad my GB-100 is working fine.

BTW, how can I recognize a DOS attack from logs?

Suresh Ganu


Reply via email to