I'm seeing a lot of blocked scans on port 57 in my firewall logs, many times in conjunction with a port 80 or port 21 scan. I was working under the assumption that these were related to a misconfigured port scanner, but I'm seeing them from a pretty diverse set of source addresses, so now I'm curious what they're looking for. jared ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Wed Nov 13 2002 - 01:43:19 PST