Security Incidents mailing list archives
Re: CRv2 multiple scans from same source IP
From: Chris Freeze <cfreeze () cfreeze com>
Date: Sun, 5 Aug 2001 21:58:19 -0500 (CDT)
On Sun, 5 Aug 2001, John Davidson wrote:
My W2k IIS logs show 3 CRv2 scans from the same source IP within the same minute.
Here everytime I get scanned, my Apache logs are showing a double hit. Snort is also logging the two back-to-back attempts. Another weird bit is that some hosts are hitting me again as quickly as 45 minutes. I wonder if some people are running injectors(c). I've also noticed that I'm getting hit by different hosts about every 2 mintutes. I wonder if we have hit a saturation point. Anyone thought about the total time for this to have statistically scanned the entire IP address space? Someone out there has to be a statistician.. ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- CRv2 multiple scans from same source IP John Davidson (Aug 05)
- Re: CRv2 multiple scans from same source IP Luc Pardon (Aug 05)
- Re: CRv2 multiple scans from same source IP Chris Freeze (Aug 05)
- Re: CRv2 multiple scans from same source IP Chris Freeze (Aug 05)
- RE: CRv2 multiple scans from same source IP Gareth Hastings (Aug 06)
- Re: CRv2 multiple scans from same source IP Paul Gear (Aug 06)
- Re: CRv2 multiple scans from same source IP Valdis . Kletnieks (Aug 05)
- RE: CRv2 multiple scans from same source IP robh (Aug 05)
- Re: CRv2 multiple scans from same source IP corecode (Aug 06)
- Re: CRv2 multiple scans from same source IP Lee Smith (Aug 06)
- RE: CRv2 multiple scans from same source IP Andrew Cruse (Aug 06)
- Re: CRv2 multiple scans from same source IP Ryan Russell (Aug 06)
- Re: CRv2 multiple scans from same source IP Andy Berkheimer (Aug 06)
- Re: CRv2 multiple scans from same source IP corecode (Aug 07)
- Re: CRv2 multiple scans from same source IP Lee Smith (Aug 06)
- Re: CRv2 multiple scans from same source IP Luc Pardon (Aug 05)
