Security Incidents mailing list archives
Re: Antw: Re: Scans from reserved addresses??
From: bryan () VISI COM (Bryan Andersen)
Date: Thu, 11 May 2000 14:00:10 -0500
Ralf Günthner wrote:
Bryan, it's even a little more complicated: The target address is not one of my own systems, but one belonging to our ISP. Our firewall just sees them pass by, I guess. I forwarded my firewall logs to the ISP but haven't heard anything since. But this stuff keeps clogging up my logfiles...I at least wanted to get a few more pointers before bugging them again.
What direction are they comming at your fire wall? From the inside or outside? If they are comming from the inside I'd start looking for the source host. From the outside, I'd block them and talk to the ISP. You should only be seeing traffic for your subnet on your link from the ISP. -- | Bryan Andersen | bryan () visi com | http://softail.visi.com | | Buzzwords are like annoying little flies that deserve to be swatted. | | -Bryan Andersen |
Current thread:
- Antw: Re: Scans from reserved addresses?? Ralf Günthner (May 11)
- <Possible follow-ups>
- Re: Antw: Re: Scans from reserved addresses?? Bryan Andersen (May 11)