We are seeing the identical except it is icmp (3/1) instead of (3/2). jcs -----Original Message----- From: Glenn Forbes Fleming Larratt [mailto:glrattat_private] Sent: Monday, June 04, 2001 9:49 AM To: incidentsat_private Subject: ICMP code 3 type 2 scans? Never seen these before this week, and now have two in rapid succession. New exploit? I *know* that my whole Class B is not banging on that one 24-net host, especially the unallocated subnets :| -g -- Glenn Forbes Fleming Larratt The Lab Ratt (not briggs :-) glrattat_private http://www.io.com/~glratt There are imaginary bugs to chase in heaven. Jun 4 02:21:11 icmp 24.77.68.1 -> my.net.136.230 (3/2), 1 packet Jun 4 02:21:15 icmp 24.77.68.1 -> my.net.211.187 (3/2), 1 packet Jun 4 02:21:16 icmp 24.77.68.1 -> my.net.36.253 (3/2), 1 packet Jun 4 02:21:26 icmp 24.77.68.1 -> my.net.97.11 (3/2), 1 packet
This archive was generated by hypermail 2b30 : Tue Jun 05 2001 - 14:55:42 PDT