[Dshield] Anyone else??
trancedylan at blueyonder.co.uk
Tue Jul 2 14:31:50 GMT 2002
It's just a shot in the dark, but have you ruled out someone on the network
attaching to "windows update" and then quitting the conn b4 the update has
----- Original Message -----
From: "Erik J. Varney" <erik at centralsecurity.net>
To: "DShield Mailing List" <list at dshield.org>
Sent: Tuesday, July 02, 2002 1:39 PM
Subject: [Dshield] Anyone else??
> Is anyone else seeing continuous (non-stop) traffic from 126.96.36.199, it
> is hitting our network block and looking for port 80?
> Microsoft (NETBLK-MICROSOFT-GLOBAL-NET)
> One Redmond Way
> Redmond, WA 98052
> Netname: MICROSOFT-GLOBAL-NET
> Netblock: 188.8.131.52 - 184.108.40.206
> Microsoft (ZM39-ARIN) noc at microsoft.com
> Domain System inverse mapping provided by:
> DNS1.CP.MSFT.NET 220.127.116.11
> DNS2.CP.MSFT.NET 18.104.22.168
> DNS1.TK.MSFT.NET 22.214.171.124
> DNS1.DC.MSFT.NET 126.96.36.199
> DNS1.SJ.MSFT.NET 188.8.131.52
> Record last updated on 20-Jun-2001.
> Database last updated on 1-Jul-2002 20:10:52 EDT.
More information about the list