[Dshield] Port 23 activity spike

Johannes B. Ullrich jullrich at sans.org
Mon Dec 29 11:26:21 GMT 2003

> I notice that recent DShield data show a spike in activity on port 23: 
> <http://isc.incidents.org/port_details.html?port=23&repax=1&tarax=2&srcax=2
> &percent=N&days=40&Redraw=>.

This spike looks like a scan hitting one of our large class B
submitters. Telnet is a popular scanned service. I presume that
all they are looking for it weak passwords.

CTO SANS Internet Storm Center               http://isc.sans.org
phone: (617) 786 1563            
  fax: (617) 786 1550                          jullrich at sans.org

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://www.dshield.org/pipermail/list/attachments/20031229/b3e3e329/attachment.bin

More information about the list mailing list