Have you queried the DShield database for the hosts you are seeing? http://www.dshield.org/ipinfo.html?ip= add the IP after the =
> -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On > Behalf Of Rich Sena > Sent: Thursday, March 06, 2008 12:02 PM > To: NANOG > Subject: Scan traffic from 121.8.0.0/16 > > > Anyone seeing anything similar - trying to determine if this > is spoofed etc... > > -- > Rich Sena - [EMAIL PROTECTED] > ThickNET Consulting > "On the way to understanding; you understand, and forget." > >
