Security Incidents mailing list archives

Re: CRv2 multiple scans from same source IP


From: Chris Freeze <cfreeze () cfreeze com>
Date: Sun, 5 Aug 2001 22:25:08 -0500 (CDT)

On Mon, 6 Aug 2001, Luc Pardon wrote:

  Maybe this is just three systems behind the same proxy ? Not untypical
for cable ISP's.

Not that I've seen.  These IP's resolve to hostnames similar @home
personal hostnames.  As an example..

cXXXXXXX-a.nirving1.tx.home.com (and several hosts where XXXXXXX is just
slightly different) show up with double hits in Snort.  It and several
others like it also rescan about every 45 minutes.



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: