I was wondering if anyone had noticed port scanning recently. In
particular, I was scanned by freon.republic.k12.mo.us on the evening of
Aug 15th at ~11:35. About an hour to an hour and a half later almost the
exact same sequence of scans came from ts2-102-ppp.ipass.net. Normally,
I'd shrug this off, but similar scans (from the same addresses) were made
on machines where I work at UT. So now I'm wondering if somebody was
methodically portscanning all of UT, or what? If anybody noticed similar
activity, or would be so kind as to look through their logs, I'd be
interested to see your info. (I probably keep more detailed logs than
most (every tcp connection to my box), but if you're running a web server
it definitely shows up as a scan for several cgi scripts (phf, test-cgi,
handler) ).
Thanks for any help.
Shane Williams
---------------------------------------------------------------------------
Send administrative requests to [EMAIL PROTECTED]