Re(2): [Dshield] Port 10/tcp scans

Ken Eichman keichman at cas.org
Thu Dec 11 19:43:45 GMT 2003


John,

> I wondered about the fact that, below, you seem to be sending back
> ACK's -- whatever is out there is sending *you* ACK/FIN's and ACK's --
> which suggests that you've got something listening and responding on
> TCP:10.
>
> Was the host on your end, below, the honeypot you mention above?

Yes, exactly. I have no idea what the scans are looking for on port 10
and I was trying to get an idea.

Ken




More information about the list mailing list