[Dshield] New probe?

Mrcorp mrcorp at yahoo.com
Sat Mar 15 22:26:43 GMT 2003


I just want to add that I will be posting much data that has been captured in ethereal and
Checkpoint logs for 2 of the honeypots in the infosecwriters honeynet.  Attacks are definetly on
the rise.  In a 6 hour period from midnight to 6 am, I logged 80000 entries in the honeynet.  All
inbound.  Is it me or is it war on the Internet?

Charles

--- "Jon R. Kibler" <Jon.Kibler at aset.com> wrote:
> We have noticed what appears to be a new probe pattern. The intruder hits first port 80 (http),
> then 57 (what exactly is 57?), then 21 (ftp), in that order, and there is about 3 seconds
> between each probe.
> 
> Any idea what this probe is and what it is trying to accomplish?
> 
> Thanks!
> 
> Jon R. Kibler
> A.S.E.T., Inc.
> Charleston, SC  USA
> 
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list


__________________________________________________
Do you Yahoo!?
Yahoo! Web Hosting - establish your business online
http://webhosting.yahoo.com



More information about the list mailing list