[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re[2]: [cobalt-users] portsenty



 
> On 2/20/04 9:00 AM, "Dan Kriwitsky" wrote:

>>>> I have been seeing a lot of attackalerts on our RAQ2 like
>>> this lately:
>>>> 
>>>> Feb 20 04:42:32 admin portsentry[1312]: attackalert: Connect from
>>>> host: client302.gdal1.hawkcommunications.com/64.63.216.141 to TCP
>>>> port: 1080
>> 
>> Anyway, I suggest taking the log and passing it to the
>> admin(s) at hawkcomms for a start. :)
>> 
>> http://www.abuse.net/lookup.phtml?DOMAIN=hawkcommunications.com

> Has anyone ever had any luck or action taken from reporting these things. We
> do it occasionally when we have time, but seems like it is going into a
> Dev/Null file. Still see the kiddies attempting to find open ports or FTP
> spots for their warez.

I used to report them, but haven't for the last few months - since (I
think) Blaster increased the daily total to +50.  I'm still getting
lots every day - am I the only one or do others get lots?

Regards
                      
Jackie

www.upton.uk.net

***** Virus-Scanned by MailScanner-4.10 *****
A service for domains hosted at upton.uk.net