On Tue, 11 Apr 2000 [EMAIL PROTECTED] wrote:
> This is a little more than a 'casual' scan. A short excerpt from my logs
> is included. There are periods where in excess of 300 packets are minute
> are being received -- hence my query about an attack.
>
> And this is not retrying on any other IP's on my network. Although the
> number of source IP's would seem to indicate an attack attempt - as it
> makes it hard to tell who the real source of the packets is.
Have you done any investigating?
The logs you posted show a US host {closest I can get is
edge2-fa0-0-0.scrm01.pbi.net} - unlikely to be a commercial enquiry
gone wrong, and CWIP-T-009-p-94-150.tmns.net.au - which may or may not be
a commercial enquiry gone wrong, but most likely isn't.
Sounds like some script kiddies have found a nice new hole in NT they're
trying to exploit.
I'd be checking logs, tracerouting and then contacting the ISP's in
question, asking for explainations.
DaZZa
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text