I'd like to thank everyone that responded to my post on the increased ftp traffic. The follow-up is, is that my box that was receiving the scans was taken out yesterday morning. Gone, fried, whatever - unrecoverable. I had some very massive attacks on the box which was the (Extranet)web server. The box was froze - totally unresponsive. After reboot, the system would not come up even with using the emergency boot disk. Attempted to rerun an upgrade of the system and got an error that it could not find the drive - that's a liberal interpretation of the message. So, those ftp scans, probes, or whatever, were a precursor to an attack coming from 4 different ip's, one right after the other. Thanks to all and I guess we are all indeed sheep in a valley of wolves. Greg Kane ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Fri Apr 26 2002 - 09:40:49 PDT