Security Incidents mailing list archives
Re: CRv2 multiple scans from same source IP
From: Chris Freeze <cfreeze () cfreeze com>
Date: Sun, 5 Aug 2001 22:25:08 -0500 (CDT)
On Mon, 6 Aug 2001, Luc Pardon wrote:
Maybe this is just three systems behind the same proxy ? Not untypical for cable ISP's.
Not that I've seen. These IP's resolve to hostnames similar @home personal hostnames. As an example.. cXXXXXXX-a.nirving1.tx.home.com (and several hosts where XXXXXXX is just slightly different) show up with double hits in Snort. It and several others like it also rescan about every 45 minutes. ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- CRv2 multiple scans from same source IP John Davidson (Aug 05)
- Re: CRv2 multiple scans from same source IP Luc Pardon (Aug 05)
- Re: CRv2 multiple scans from same source IP Chris Freeze (Aug 05)
- Re: CRv2 multiple scans from same source IP Chris Freeze (Aug 05)
- RE: CRv2 multiple scans from same source IP Gareth Hastings (Aug 06)
- Re: CRv2 multiple scans from same source IP Paul Gear (Aug 06)
- Re: CRv2 multiple scans from same source IP Valdis . Kletnieks (Aug 05)
- RE: CRv2 multiple scans from same source IP robh (Aug 05)
- Re: CRv2 multiple scans from same source IP corecode (Aug 06)
- Re: CRv2 multiple scans from same source IP Lee Smith (Aug 06)
- RE: CRv2 multiple scans from same source IP Andrew Cruse (Aug 06)
- Re: CRv2 multiple scans from same source IP Ryan Russell (Aug 06)
- Re: CRv2 multiple scans from same source IP Andy Berkheimer (Aug 06)
- Re: CRv2 multiple scans from same source IP Lee Smith (Aug 06)
(Thread continues...)
- Re: CRv2 multiple scans from same source IP Luc Pardon (Aug 05)