Security Incidents mailing list archives
Re: Aggresive RPC & DNS scans from Korean hosts
From: "Matt W." <kmx () EGATOBAS ORG>
Date: Tue, 20 Mar 2001 11:56:31 -0600
I've been seeing traffic from this host for about a week. Started with SYN scans for port 21/53/111/ and i've been sweeped for 53/111 twice in the last 3 days. -matt www.farm9.com Managed Security Services. Joseph Nicholas Yarbrough wrote:
In the spirit of owned korean hosts, a we have been getting aggresive scans from 203.232.4.4 on tcp/53 and tcp/111. (perhaps more) -Nick
Current thread:
- Strange accumulation of scans from Korea (KORNET/HANANET) Ralf G. R. Bergs (Mar 09)
- Re: Strange accumulation of scans from Korea (KORNET/HANANET) John (Mar 09)
- Re: Strange accumulation of scans from Korea (KORNET/HANANET) Ralf G. R. Bergs (Mar 14)
- Aggresive RPC & DNS scans from Korean hosts Joseph Nicholas Yarbrough (Mar 20)
- Re: Aggresive RPC & DNS scans from Korean hosts dano (Mar 20)
- Re: Aggresive RPC & DNS scans from Korean hosts Matt W. (Mar 20)
- Re: Strange accumulation of scans from Korea (KORNET/HANANET) Ralf G. R. Bergs (Mar 14)
- Re: Strange accumulation of scans from Korea (KORNET/HANANET) John (Mar 09)