[Dshield] Got an interesting one trapped in the tarpit...
ed.truitt at etee2k.net
Mon Sep 23 11:46:29 GMT 2002
This morning, when I checked LaBrea, I noticed one IP (184.108.40.206) with
56 threads caught. Checking it out further, I noticed that it was trying to
hit the following ports: 80, 3128, 8080, and 6588. I know what the first
three are for, but the last one I am unfamiliar with. Any ideas as to what
type of attack this is, what "script" the kiddies are using here? I have
not seen this one before.
PGP fingerprint: 5368 D25E 468C A250 9833 CCD6 DBAE 9C25 02F9 0AB9
"Note to spammers: my 'delete' key is connected to YOUR ISP.
Also, if you send me UCE, I reserve the right to post your spew
on my Web site, with the appropriate color commentary, so that
others may have a good laugh at your expense."
More information about the list