Firewall Wizards mailing list archives

TCP port 7 traffic from DoubleClick


From: Greg Nowicki <greg () mikon com>
Date: Thu, 01 Jul 1999 18:55:31 EDT

My firewall has been logging a persistent stream of TCP connection attempts
to port 7 (echo) from six hosts belonging to DoubleClick.  I would like to
know if anyone else on the list has observed this? 

It started back on June 4 and has continued almost every day since then.
The pattern of the traffic consists of 2-6 connection attempts from the
addresses 199.95.207.91, 199.95.208.85, 207.239.35.71, 208.32.211.71,
209.67.38.49, & 209.67.38.50.  Each host will attempt a connection within
30 seconds or so of the others.  This pattern repeats 1-4 times a day.

The reason that I do not just ignore the traffic is that the frequency
of the attempts exceeds thresholds I have set on my firewall thereby
generating a page.  I can only speculate that they are trying to gauge
the performance of their banner ad delivery.  E-mail requests to
DoubleClick have gone unanswered.  I have reported the traffic to the
abuse group of my ISP and they are looking in to it.

--
------------------------------------------------------------------------
Greg Nowicki                    email: greg () mikon com
MIKON Systems, Inc.             phone: 770.804.5885
6 Concourse Pkwy Ste 360        fax  : 770.804.5886
Atlanta, GA  30328-5351         URL  : http://www.mikon.com

MIKON - Software for the continuous improvement of quality and cost (TM)
------------------------------------------------------------------------



Current thread: