Security Incidents mailing list archives

Scan of ports 100 and 510


From: Len Burns <lenb () SASQUATCH COM>
Date: Sun, 26 Nov 2000 22:47:52 -0800

Hi,

Earlier this evening, I observed the following scan of most of our
class C subnets:
Nov 26 17:45:12 208.185.167.115:510 -> xxx.xxx.xxx.240:100 SYN ******S*
And then 2 hours later:
Nov 26 19:45:11 208.185.167.115:510 -> xxx.xxx.xxx.240:510 SYN ******S*
(Logs in GMT-800)

Researching this a bit all I could find is
newacct  100/tcp   unauthorized use
fcp   510/tcp   FirstClass Protocol

I am not grasping the significance.  Thoughts?


-Len


Current thread: