On Tue, 11 Apr 2000 [EMAIL PROTECTED] wrote:

> This is a little more than a 'casual' scan.  A short excerpt from my logs 
> is included.  There are periods where in excess of 300 packets are minute
> are being received -- hence my query about an attack.
> 
> And this is not retrying on any other IP's on my network.  Although the
> number of source IP's would seem to indicate an attack attempt - as it
> makes it hard to tell who the real source of the packets is.

Have you done any investigating?

The logs you posted show a US host {closest I can get is
edge2-fa0-0-0.scrm01.pbi.net} - unlikely to be a commercial enquiry
gone wrong, and CWIP-T-009-p-94-150.tmns.net.au - which may or may not be
a commercial enquiry gone wrong, but most likely isn't.

Sounds like some script kiddies have found a nice new hole in NT they're
trying to exploit.

I'd be checking logs, tracerouting and then contacting the ISP's in
question, asking for explainations.

DaZZa


--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to