[Dshield] Internap

Paul Marsh pmarsh at nmefdn.org
Wed Mar 23 16:11:35 GMT 2005


	
	Once again I'm asking the list to educate me. I'm sure some are
getting tired of the stupid questions, sorry ;)

	I've been noticing the following IP's scanning me with the
following source ports.

	206.253.195.6 33435 udp
	206.253.195.10 33436 udp
	206.253.195.14 33437 udp
	206.253.195.18 33438 udp
	206.253.195.26 33440 udp

	The range belongs to internap.com.  Their site mentions router
optimization services.  Does traceroute us the ports in question?  While
reviewing port reports on dshield I noticed the output of the port query
on the ports in question to be very systematic.  I said to my self, self
this has got be internap's router optimization services scanning the
internet for OSPF.  I dug a little deeper and found the following
http://isc.sans.org/aslookup.php?as=6993 

	The question is, what are these scans?

	Why are they listed as infected?  

Thanx, Paul 




More information about the list mailing list