Firewall Wizards mailing list archives

finger/IMAP scans


From: Neil Ratzlaff <Neil.Ratzlaff () ucop edu>
Date: Mon, 22 Mar 1999 09:59:22 -0800

I keep seeing people doing combination finger/IMAP scans on our primary and
secondary nameservers.  The number of sources is increasing.  (And the
firewall keeps blocking them.) The ratio is usually about two fingers
followed by an IMAP, they wil try several dozen times, and then they quit.
Does anyone recognize this as a meaningful pattern?  If so, can someone
tell me what they think they are doing?  Assuming there is thought
involved, of course.

Thanks,
Neil



Current thread: