[prev in list] [next in list] [prev in thread] [next in thread] 

List:       focus-ids
Subject:    Re: Scans from Netherlands
From:       "Mahn, Chris" <chmahn () DUKE-ENERGY ! COM>
Date:       2001-01-30 12:40:56
[Download RAW message or body]

Sorry about that. I knew I'd omit information that was needed to answer the
question.

 We received them the morning of the 26th of January. They were using
protocol 255 (undefined). We received quite a few going to our broadcast
addresses on port 40. They all originated from port 17664.

--Chris




                    Crook
                    Drew-MCG32195          To:     "'chmahn@DUKE-ENERGY.COM'"
                    <Drew.Crook@mot        <chmahn@DUKE-ENERGY.COM>
                    orola.com>             cc:
                                           Subject:     RE: Scans from Netherlands
                    01/29/01 04:25
                    PM






What kinds of scans and when?
Canonical name: cal009307.student.utwente.nl
Addresses:
  130.89.222.57

-----Original Message-----
From: Mahn, Chris [mailto:chmahn@DUKE-ENERGY.COM]
Sent: Monday, January 29, 2001 5:42 AM
To: FOCUS-IDS@SECURITYFOCUS.COM
Subject: Scans from Netherlands


  Has anybody received any scans from University Twenty in the Netherlands.
The source IP address is 130.89.222.57. Thanks

Chris Mahn

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic