[Dshield] Port scans

Abuse abuse at what4now.com
Wed Mar 16 06:22:54 GMT 2005


** Reply to message from admin <admin at bartonphillips.com> on Tue, 15 Mar 2005
10:34:57 -0800

> When I look at my log files I see that I get many more port scans from 
> the same IP range as mine. I am with SBC in LA and my IP is 
> 68.122.xxx.xxx and most of the port scans and MS junk is all from others 
> with this IP range. What am I missing? What is it about the Net topology 
> that makes most of the junk come from the same range? This is a serious 
> question, I really would like to know.

It could be SBC scanning for something.  My ISP did scan for some ports at one
time but they have since quit doing it.

Most likely it is trojaned machines on your subnet trying to propagate.  When I
get those I notify my ISP, I don't think they want to hear about it but they do
get it stopped.



More information about the list mailing list