> 	We saw a largely unsuccessful (although I just saw a report that a 
> user on that subnet has removed a machine they believe was compromised) 
> ping/port 57/port 80 scan from on the morning of the 17th down
> one of our class Cs.  I'll have to have a closer look for a longer time on the 
> host reported possibly compromised and see what happened.

We got one of these scans tonight - it not only probed for ports 80 and
57, it tried the IIS cmd.exe and root.exe (Code Red) exploits.  The
scan came from, a host at the Univ of Puerto Rico.

