My guess would be that your ip got picked as a decoy for someone's port scan. So you were seeing the target system's replys. Not sure what would have caused your system to go down, though. > -----Original Message----- > From: Jonathan A. Zdziarski [mailto:jonathanat_private] > Sent: Monday, December 10, 2001 8:02 AM > To: incidentsat_private > Subject: Possible DoS Attack? > > > I normally disregard scans, however this particular scan doesn't > look like a > conventional port scan, and it happened around the same time the machine > went down. It looks like their source port is changing, but the > target port > on our machine is only changed periodically. Could this have been a DoS > attack? ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Mon Dec 10 2001 - 12:50:25 PST