[Dshield] UDP 137 Scans
jsage at finchhaven.com
Tue Aug 12 23:49:16 GMT 2003
On Tue, Aug 12, 2003 at 01:21:41PM -0700, John Sage wrote:
> Jon, et al:
Relative volumes of TCP:135, TCP:4444, and UDP:137 since about 23:00
last night; context, dialup into AT&T's Seattle WA POP
TCP:135 - 3001
TCP:4444 - 1669
UDP:137 - 447
I'm seeing almost nothing but 12.82's and 12.81's -- I'm at 12.82.x.x
I just did a real quick-n-dirty grep ':135' alert.full |sort -k 2
|uniq -f 1, and I think the count is about 456 unique source IP's...
"Obviously, we do not want to leave zombies around."
See our exciting, all-new look! http://www.finchhaven.com/
Note: The isc at incidents.org email address is an alias for a
mailing list of approximately 30 volunteer incident handlers.
You may receive responses from other individuals on that list.
Please direct all communications to isc at incidents.org, so that
everyone is kept "in the loop".
More information about the list