I'd say it's more likely to be a DoS against windows, perhaps a little
verbose
logging of the attacks are in order?

What protocol, tcp or udp?
Are they coming from the same IP range, or all different?
(And check whether the same attack has multiple IP's in the
same barrage of packets, this would almost certainly indicate a
spoofing DoS attack)

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of
[EMAIL PROTECTED]
Sent: Monday, 10 April 2000 12:10 PM
To: [EMAIL PROTECTED]
Subject: [SLUG] Possible hack attempt ?



Hi all,

Does anybody know of a hack against Samba that is making the rounds and
anything else that likes to send a lot of packets to port 137 - regardless
of whether a connection was estblished or not ?

My sites are being hit by a constant barrage of packets for port 137 - all
of which are being blocked by the firewall, but the number of them is
disconcerting.

Cheers
Jason.

---
Jason Ball
Electronic Commerce Specialist
Corporate Express Australia Ltd
Phone: +61 2 9335 0374  Fax: +61 2 9335 0753
Email: [EMAIL PROTECTED]


--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text


--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to