[Dshield] Re: Port 135 scans

John Sage jsage at finchhaven.com
Thu Sep 11 16:33:10 GMT 2003


On Thu, Sep 11, 2003 at 11:12:24AM -0500, Doug White wrote:
> After withstanding 1700 + port 135 scans daily on one machine for
> the past two weeks, as of midnight last night they have suddenly
> stopped altogether.   I have made no changes at the perimeter. 
> Anyone able to shed some light on this change?

In what context? Single user at home, or business, or what?

Long story short: has your upstream (finally) instituted ingress
filtering into the IP address space your connection has?

- John
"Warning: time of day goes back, taking countermeasures."

More information about the list mailing list