Snort mailing list archives

Re: Huge SYN Scan


From: Erik Fichtner <emf () servervault com>
Date: Wed, 19 Dec 2001 12:21:34 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Dec 19, 2001 at 04:46:20PM +0100, Roberto Suarez Soto wrote:
Anyone else seeing massive SYN scans to port 80 from all over the
'net?

      Effect of CodeRed/Nimda infected computers, I would say. There are a
lot of them, though the "prime time" of the virus has passed :-)

Nah, there's something else out there too.   I've spotted a couple of
SYN scans to 80/tcp that don't result in an http query over the past month 
or two..    

No idea what it is, though.


- -- 
Erik Fichtner
Security Administrator, ServerVault, Inc.
703-333-5900
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE8IMydQ7EzrewLMS0RAqFEAJ0Yk33FAemTMEp219NiRje5mhtdCACgnGEP
LvTe5e0w1kg+gToSdf6fMUo=
=NChv
-----END PGP SIGNATURE-----

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: