Security Incidents mailing list archives

6112/TCP scans


From: Paul Dokas <dokas () cs umn edu>
Date: Fri, 7 Dec 2001 15:14:16 -0600


Is anyone else seeing large numbers of 6112/TCP scan coming from
63.240.0.0 - 63.242.255.255?  I'm seeing about 10/minute destined to
random IPs within my networks.  The scanning technique looks exactly
like the TCPMUX scans that were occuring a few months ago (forgive me,
I can't remember what the technique was, just that it was really odd).

Obviously, they're looking for vulnerable CDE installations.

Paul
-- 
Paul Dokas                                            dokas () cs umn edu
======================================================================
Don Juan Matus:  "an enigma wrapped in mystery wrapped in a tortilla."

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: