Security Incidents mailing list archives

Re: Aggresive RPC & DNS scans from Korean hosts


From: "Matt W." <kmx () EGATOBAS ORG>
Date: Tue, 20 Mar 2001 11:56:31 -0600

I've been seeing traffic from this host for about a week.  Started with SYN
scans for port 21/53/111/ and i've been sweeped for 53/111 twice in the last 3
days.

-matt
www.farm9.com
Managed Security Services.

Joseph Nicholas Yarbrough wrote:

In the spirit of owned korean hosts, a we have been getting aggresive scans
from 203.232.4.4 on tcp/53 and tcp/111. (perhaps more)

-Nick


Current thread: