[Dshield] Anybody saw this? scans on port 179

Ed Truitt ed.truitt at etee2k.net
Wed Aug 28 12:29:06 GMT 2002


Port 179 appears to be for BGP (Border Gateway Protocol, used by routers
IIRC.)  I haven't seen any indications of such a scan against me in the last
30 days.  I wonder, do you have the IP(s) that are doing the scanning?  Does
it look like one host is doing all the scanning (in a particular "episode"),
or more like a bunch of machines scanning in parallel?

Cheers,
Ed Truitt
PGP fingerprint:  5368 D25E 468C A250 9833  CCD6 DBAE 9C25 02F9 0AB9
http://www.etee2k.net
http://www.bsatroop148.org

"Note to spammers:  my 'delete' key is connected to YOUR ISP.
 Also, if you send me UCE, I reserve the right to post your spew
on my Web site, with the appropriate color commentary, so that
others may have a good laugh at your expense."

----- Original Message -----
From: Lacroix, Yves
To: list at dshield.org
Sent: Wednesday, August 28, 2002 4:04 AM
Subject: [Dshield] Anybody saw this? scans on port 179


I got numerous scans on my hole IP range since August 25th on port 179.

I was just wondering because I never had this before.

The scans are not very often but the number of requests is pretty high when
a scan start!

So if someone noticed it or has an idea

Regards
Yves


Yves Lacroix
Resp. Internet & Telecoms
MEGTEC Systems SA

Tel: +33 (0)1 69 89 49 93
Fax: +33 (0)1 64 97 74 14
Mail: yves.lacroix at meg.fr




More information about the list mailing list