[Dshield] Anyone else??

TranceDylan trancedylan at blueyonder.co.uk
Tue Jul 2 14:31:50 GMT 2002


Hi,
It's just a shot in the dark, but have you ruled out someone on the network
attaching to "windows update" and then quitting the conn b4 the update has
completed?
tD


----- Original Message -----
From: "Erik J. Varney" <erik at centralsecurity.net>
To: "DShield Mailing List" <list at dshield.org>
Sent: Tuesday, July 02, 2002 1:39 PM
Subject: [Dshield] Anyone else??


> Is anyone else seeing continuous (non-stop) traffic from 207.46.138.20, it
> is hitting our network block and looking for port 80?
>
> Microsoft (NETBLK-MICROSOFT-GLOBAL-NET)
>    One Redmond Way
>    Redmond, WA 98052
>    US
>
>    Netname: MICROSOFT-GLOBAL-NET
>    Netblock: 207.46.0.0 - 207.46.255.255
>
>    Coordinator:
>       Microsoft  (ZM39-ARIN)  noc at microsoft.com
>       425-936-4200
>
>    Domain System inverse mapping provided by:
>
>    DNS1.CP.MSFT.NET 207.46.138.20
>    DNS2.CP.MSFT.NET 207.46.138.21
>    DNS1.TK.MSFT.NET 207.46.232.37
>    DNS1.DC.MSFT.NET 207.68.128.151
>    DNS1.SJ.MSFT.NET 207.46.97.11
>
>    Record last updated on 20-Jun-2001.
>    Database last updated on  1-Jul-2002 20:10:52 EDT.
>
>
> Erik
>
>




More information about the list mailing list