[41418] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: FTP Probes from Taiwan/China

daemon@ATHENA.MIT.EDU (Stephen J. Wilcox)
Sun Sep 9 05:59:28 2001

Date: Sun, 9 Sep 2001 10:58:49 +0100 (BST)
From: "Stephen J. Wilcox" <steve@opaltelecom.co.uk>
To: Gordon Ewasiuk <gewasiuk@gnmc.net>
Cc: nanog@merit.edu
In-Reply-To: <Pine.GSO.4.33.0109090009490.5653-100000@enterprise.gnmc.net>
Message-ID: <Pine.LNX.4.21.0109091048510.10367-100000@staff.opaltelecom.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu



Maybe I'm not getting attacked in the same way as you - perhaps its
someone directing DoS at you or something? But I am seeing a massive
increase in scans from lots of IPs and to lots of ports.

Steve

On Sun, 9 Sep 2001, Gordon Ewasiuk wrote:

> 
> 
> Has anyone seen a dramatic increase in FTP probes/scans/bad stuff from
> certain IP blocks in Taiwan or China?  Specifically, 211/8, 61/8, and
> 202/7.  I'm logging over 7500 probes/hr right now.  Is there a new
> exploit out or something?
> 
> Another network just surfaced:  210.82/15
> 
> -Gordon
> 
> --------------------------------------------------
> Gordon Ewasiuk, Certifed Sun Fanatic,  Winstar VHC
> The REAL office number is here----->  703.893.4901
> Tired of BSODs, My Computer, and Code Red?
> http://www.sun.com/solaris/binaries/
> -------------------------------------------------
> 
> 

-- 
Stephen J. Wilcox
IP Services Manager, Opal Telecom
http://www.opaltelecom.co.uk/
Tel: 0161 222 2000
Fax: 0161 222 2008


home help back first fref pref prev next nref lref last post