This is a little more than a 'casual' scan.  A short excerpt from my logs 
is included.  There are periods where in excess of 300 packets are minute
are being received -- hence my query about an attack.

And this is not retrying on any other IP's on my network.  Although the
number of source IP's would seem to indicate an attack attempt - as it
makes it hard to tell who the real source of the packets is.

Cheers
Jason.

-----

Apr 11 15:57:13 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
206.170.162.188/1044 to 10.250.1.6/137 
Apr 11 15:57:14 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
206.170.162.188/1044 to 10.250.1.6/137 
Apr 11 15:57:14 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
206.170.162.188/1024 to 10.250.1.6/137 
Apr 11 15:57:16 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
206.170.162.188/1044 to 10.250.1.6/137 
Apr 11 15:57:16 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
206.170.162.188/1024 to 10.250.1.6/137 
Apr 11 16:23:31 firewall1.ce.com.au %PIX-2-106006: Deny inbound UDP from
139.134.94.150/137 to 10.250.1.140/137 
Apr 11 16:24:56 firewall1.ce.com.au last message repeated 6 times
Apr 11 16:26:16 firewall1.ce.com.au last message repeated 282 times
Apr 11 16:27:30 firewall1.ce.com.au last message repeated 21 times

----





--- 
Jason Ball 
Electronic Commerce Specialist 
Corporate Express Australia Ltd 
Phone: +61 2 9335 0374 Fax: +61 2 9335 0753 Email: [EMAIL PROTECTED]

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to