[102881] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Scan traffic from 121.8.0.0/16

daemon@ATHENA.MIT.EDU (Jon R. Kibler)
Thu Mar 6 15:18:32 2008

Date: Thu, 06 Mar 2008 15:10:39 -0500
From: "Jon R. Kibler" <Jon.Kibler@aset.com>
To: Rich Sena <ras@thick.net>
CC: NANOG <nanog@merit.edu>
In-Reply-To: <Pine.LNX.4.64.0803061500590.21778@noc1>
Errors-To: owner-nanog@merit.edu


This is a multi-part message in MIME format...

------------=_1204834370-514-366
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Rich Sena wrote:
> 
> Anyone seeing anything similar - trying to determine if this is spoofed 
> etc...
> 

Why would you think it is a problem? It's China Telecom. What else would you expect?

Off the sarcastic and onto the serious, I am seeing hits on 53/UDP and 25/TCP from a couple of hosts in that netblock.

 From my experience, these are probably spambots.

Jon K.

-- 
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
m: 843-224-2494




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


------------=_1204834370-514-366--


home help back first fref pref prev next nref lref last post