[Dshield] Sub7 / port 27374

Johannes Ullrich jullrich at sans.org
Thu Jul 11 19:36:57 GMT 2002


In most cases, Sub7 scans originate from IRC controlled bots. They usually scan certain IP ranges only.
As a result, users in these IP ranges will experience a surge in scans.


On Thu, 11 Jul 2002 13:54:07 -0400
"Richard Golodner" <RGolodner at aetea.com> wrote:

> 
> 	RipTech Managed Security Services had sent me an email stating that
> Sub-Seven scans were on the up-swing with a noted trend that the majority of
> these scans were originating from Korea. 
> 						Rich
> 
> _______________________________________________
> Dshield mailing list
> Dshield at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list


-- 
---------------------------------------------------------------
jullrich at sans.org             Collaborative Intrusion Detection
                                    join http://www.dshield.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://www.dshield.org/pipermail/list/attachments/20020711/d591df63/attachment.bin


More information about the list mailing list