Security Incidents mailing list archives

Re: Odd UPD scan


From: rw () ANOTHER DE (Rainer Weikusat)
Date: Fri, 17 Mar 2000 17:19:35 +0100


David Meissner <dmeissner () PUNCHNETWORKS COM> writes:
I've seen the same activity from source addresses like
10.2.2.1. Maybe they're trying to guess our internal network
numbers, but what would be the point?

Can anyone suggest what might be going on?

Nothing? Could simply be a misconfiguration at the other end. RFC1918
addresses show up quit regularly in the logs over here.

Rainer

--
- sig lost -



Current thread: