At 10:57 PM 1/11/2003 -0600, you wrote:
I'm getting a lot of the below, looks like someone is going through all the domains and IPs on my cobalt (via www) --is this normal or someone is scanning my ports or DoS attack my web server?
One of my servers was getting SYN flooded late last week as well. As was mentioned earlier on this list, in the case of these DoS attacks, you can't trust the actual IP address has not been forged, so trying to do an all out banning of the IP address(es) may not lead you anywhere. Fortunately for me, I waited out the attack which didn't last long, and things got back to normal.