On Fri, 20 Jul 2001, Dean Cunningham wrote: > Looks like code red , but not seeing the 3 hits per ip address, just one. > May be due to the different FW logs, I use Firewall-1. > I was getting three SYN packets per attempt. For simple port-blocking firewalls, they may log it as three entries. Firewall-1 will treat it as one "connection" attempt, and log it as a single item. Ryan ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Thu Jul 19 2001 - 23:31:48 PDT