[Dshield] shawcable

Freek de Kruijf f.de.kruijf at hetnet.nl
Sun Oct 14 23:46:55 GMT 2007


Op Thursday 11 October 2007 12:19:30 schreef Altadena Internet Hostmaster:
> On a completely separate subject, but still involving the attack
> correlation software, I note that my summary reports have LOTS of hits
> from close address ranges on shawcable.  Does the software treat these
> as all one attack (this is likely...) or not?

Almost dayly I have a relatively large number of UDP packages coming from 
shawcable. Most of them going to port 1026, the rest going to ports a little 
higher.

I have no clue whether these packages are really coming from shawcable or are 
spoofed.

-- 
fr.gr.

Freek de Kruijf


More information about the list mailing list