No ideas, but I have lots of the same thing. Source port increments by one with every IP address, and it hits every machine on the network. No other activity has been noted from the source IP address, just the scan. I have seen it originate from several IP addresses. Rob Joerg Weber wrote: > > Hello everyone, > > my FW-Logs went insane last night with gazillions of connection attempts to > port 10008. > FW-1 does unfortunately not log dropped packets, so I've no idea about flags > et al, but the scan looks like this: > SourcePort = Increases with each scan > DestPort = 10008 > > This looks like an automated tool to me, as the whole scan took about a > second or two. > Any ideas? > > Thanks, > > Joerg -- Rob Lindenbusch Lead Systems Administrator accessIndiana E-mail: rlindenbuschat_private Phone: (317)233-2378 URL: http://www.IN.gov/
This archive was generated by hypermail 2b30 : Tue May 15 2001 - 10:33:55 PDT