I'm seeing the same thing. I also noticed one of the Code Red probes came at
the same time as a port57 scan from the same address yesterday.
On 11/1, I reported seeing very large IIS vulnerability probes that also
coincided with a port 57 scan.
One reply I received was that it was probably someone using "FxScanner". See
the following URL for details:
http://cert.uni-stuttgart.de/archive/intrusions/2002/11/msg00015.html > -----Original Message-----
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Thu Nov 14 02:09:37 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:50 EDT
|