Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)
On Thu, 30 Jan 2003 at 14:31:36 +1100, Keith Owens wrote:
> On Wed, 29 Jan 2003 21:46:53 +1100,
Similarly at my networks.
Yesterday evening (Jan 29 21:10 GMT+1) a very noticeable stream of such
packets started to come into my networks.
All are TCP, from 255.255.255.255(80), destined to various random
addresses (even not used) to various port numbers.
This appearance is very noticeable. Before yesterday, single packets
from 255.255.255.255 were coming in rate about one for three weeks.
Since yesterday there have been about 1680 for 22 hours.
--
Tomasz Papszun SysAdm @ TP S.A. Lodz, Poland | And it's only
tomek(at)lodz.tpsa.pl
http://www.lodz.tpsa.pl/ | ones and zeros.
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see:
http://aris.securityfocus.com
Received on Thu Jan 30 14:18:22 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:56 EDT
|