[Dshield] massive scans on 255.255.255.255:80

Robert robert at chalmers.com.au
Tue Aug 7 12:28:17 GMT 2001


yes - it's the CodeRed worm attempting to gain access.
We've been getting hit for days now, even though we have no IIS server
running, it still tries to get access and so soaks up bandwidth badly.

Robert


----- Original Message -----
From: <k.lichtenwalder at computer.org>
To: <dshield at dshield.org>
Sent: Tuesday, August 07, 2001 4:47 PM
Subject: [Dshield] massive scans on 255.255.255.255:80


> Hi,
>
> anybody else sees this? One machine I'm administering gets hit with
> Broadcast packages to port 80. It's all crushing on the firewall, but
> still. I mean, being tcp and all, what's a broadcast package worth then?
> Can you still map a subnet or so? The packages are coming from a
> multitude of different addresses.
>
> Klaus
> --
> ------------------------------------------------------------------------
>  Klaus Lichtenwalder, Dipl. Inform.,       http://www.webforum.de/Klaus/
>  Fax +49-(0)89-91072699                            Lichtenwalder at ACM.org
>  NIC: KL2100, KL76-RIPE                     K.Lichtenwalder at Computer.org
>  PGP Key fingerprint = 2658 EA97 E1A1 2680 5ECA  0036 80F5 F250 3CF8
> C2C7
>
> _______________________________________________
> Dshield mailing list
> Dshield at dshield.org
> To change your subscription options (or unsubscribe), see:
http://www1.dshield.org/mailman/listinfo/dshield
>




More information about the list mailing list