[Dshield] Please help

Johannes B. Ullrich jullrich at euclidian.com
Tue Oct 30 13:22:32 GMT 2001


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Many worms prefer to scan the local network. The port 80 hits are most 
likely due to Nimda, which is much more likely to scan IP addresses on the 
same subnet.

On Mon, 29 Oct 2001, William W wrote:

> For the past 2 weeks it seems that I've been 'under attack' by users from my
> own ISP.
> In the last 7 days alone, I have been targeted 500+ times by 24.202.X.X
> 
> Please look at the last 10 lines from my ZoneAlarm log ;
> ...

- -- 
- -------
jullrich at sans.org                    Join http://www.DShield.org
                          Distributed Intrusion Detection System

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE73qmaVOIizK5pIDMRAmBZAKCW9k2NzkvrfQffEv9YyKaSHEYYkACcDQvy
gtDu18jiiDIcQ1Lhl1chHWM=
=WojO
-----END PGP SIGNATURE-----




More information about the list mailing list