On Thu, 9 Mar 2006, Alex wrote: > Could this be a SSH scan by some stupid script kiddie that mistook the > telnet port# for that of SSH?
It would have to be a kiddie with an army of zombies at his (or her) disposal. The probes came from hundreds (if not thousands) of different IPs and a small random sample I checked was able to finish the TCP 3-way handshake (and read a server greeting and disconnect) when it probed an address where a telnet server was listening and accessible. --Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ] "Resistance is futile. Open your source code and prepare for assimilation."
