Security Incidents mailing list archives

code red scan update


From: Kevin Holmquist <kevinh () netronin org>
Date: Wed, 01 Aug 2001 17:32:50 +0000

Based on grepped weblogs, I've had two scans on my DSL network at home.

One was at 8:38am from 210.85.153.8, registered to a Cable modem ISP in Taiwan

Second was at 10:56am from 217.110.107.55, registered to a webcast group in Germany

All times US-MDT.  Registration information via www.ripe.net and www.apnic.net

both attempts had the GET /default.ida?NNNNNNN.... message.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: