continues SCAN Proxy attempt

From: Hugo van der Kooij (hvdkooijat_private)
Date: Fri May 24 2002 - 13:18:12 PDT

  • Next message: Bamm (Robert) Visscher: "Re: odd scans?"

    For over two day I am being probed by a specific IP adres as shown in this 
    small sample:
    May 24 22:08:04 vigor kernel: Packet log: if-inet DENY ppp0 PROTO=6 L=48 S=0x00 I=11804 F=0x4000 T=106 
    SYN (#36)  
    May 24 22:08:04 vigor snort[6198]: [1:615:1] SCAN Proxy attempt 
    [Classification: Attempted Information Leak] [Priority: 2]: {TCP} ->
    This occured about 1500 times in a periode of 2 days and 4 hours.
    I have yet not received any response from the owner of the netblock.
    Anyone else seen any similar activities from this netblock?
    All email send to me is bound to the rules described on my homepage.
    	    Don't meddle in the affairs of sysadmins,
    	    for they are subtle and quick to anger.
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see:

    This archive was generated by hypermail 2b30 : Fri May 24 2002 - 13:31:40 PDT