Sun Dec 28 02:10:37 GMT 2003

You got it. I have DCC and others. I restarted my Linux box after a 
kernel update and forgot I hadn't saved the ipchains info. I had added 
the DCC (etc) so they could get through my firewall.

Thanks for the heads up. I would have been scratching my head for quite 
a while on this one.

>>|         373   | dcc.uncw.edu
>>|         373   | dccpub1.neonova.net
>>|         373   | dcc.meer.net
>>|         371   | dcc.servercave.com
>>|         371   | dcc3.sihope.com
>>|         366   | 
>Two hints:
>- about half of the hosts you see in this list have a hostname 
>  like 'dcc.*'.
>- Looking at the reports in details, it looks like most of them
>  use a source port of 6277.
>"DCC" is short for "Distributed Checksum Clearinghouse". Its a 
>network of servers/clients that compare checksums for email
>messages and try to identify spam. They usually connect on port
>Did you install a spam filter recently? it kind of looks
>like you connected to one of these systems and are blocking
>the response.
>The other option is that someone is DDOS'ing them and you are
>seeing the backscatter as they happen to use your IP address.
>>All the scans are UDP from 32769 through 33718. 
>>I have gotten more today. This just started. Up until yesterday I have 
>>never seen these scans. I do occasionally get scanned but not this 
>>range and from so many different IP addresses during one day. I suspect
>> this must be some organized search. Most likely a worm or trojan. Has 
>>no one else seen this during the last couple of days?
