Security Incidents mailing list archives

Re: PING Nmap2.36BETA


From: Ryan Russell <ryan () SECURITYFOCUS COM>
Date: Mon, 29 Jan 2001 13:02:36 -0700

On Mon, 29 Jan 2001, Cristian Dumitrescu wrote:

   My router got hit with over 200 PING Nmap2.36BETA pings, on 01/27 form
13:08 ... until 17:30. Aparently, they all came from random hosts ( i
conted over 150 different hosts ).
   Could someone explain the purpose of these pings ?

NMAP has a decoy traffic feature.  One of those IPs in the list is the
real one, the others are spoofed.  See which source IP shows up most
often.  Someone is curious what OS you're running.

                                        Ryan


Current thread: