[Dshield] New probe?
mrcorp at yahoo.com
Sat Mar 15 22:26:43 GMT 2003
I just want to add that I will be posting much data that has been captured in ethereal and
Checkpoint logs for 2 of the honeypots in the infosecwriters honeynet. Attacks are definetly on
the rise. In a 6 hour period from midnight to 6 am, I logged 80000 entries in the honeynet. All
inbound. Is it me or is it war on the Internet?
--- "Jon R. Kibler" <Jon.Kibler at aset.com> wrote:
> We have noticed what appears to be a new probe pattern. The intruder hits first port 80 (http),
> then 57 (what exactly is 57?), then 21 (ftp), in that order, and there is about 3 seconds
> between each probe.
> Any idea what this probe is and what it is trying to accomplish?
> Jon R. Kibler
> A.S.E.T., Inc.
> Charleston, SC USA
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see:
Do you Yahoo!?
Yahoo! Web Hosting - establish your business online
More information about the list