[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-security] Same IP scan again and again and again
- Subject: RE: [cobalt-security] Same IP scan again and again and again
- From: "Michele Neylon:: Blacknight Solutions" <michele@xxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 15 Jul 2003 18:30:44 +0200
- Organization: Blacknight Internet Solutions Ltd
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
>
> -----Original Message-----
> From: cobalt-security-admin@xxxxxxxxxxxxxxx
> [mailto:cobalt-security-admin@xxxxxxxxxxxxxxx] On Behalf Of
> Simon Wilson
> Sent: 15 July 2003 18:23
> To: cobalt-security@xxxxxxxxxxxxxxx
>
> I am sick to death of getting this:
>
> Active System Attack Alerts
> =-=-=-=-=-=-=-=-=-=-=-=-=-=
> Jul 15 16:49:17 ns1 portsentry[1216]: attackalert: Connect from host:
> 63.215.251.101/63.215.251.101 to UDP port: 135 Jul 15
> 16:49:17 ns1 portsentry[1216]: attackalert: Host:
> 63.215.251.101 is already blocked. Ignoring
>
> OK so its not actually getting through, but this same IP
> address (level3
> apparently) has been doing this every 15 minutes for hours on
> end for weeks. I have told level3 about it countless times,
> but they don't even acknowledge my emails. Any ideas as to
> what I can do?
> What are they up to?
>
Block the port number completely
#########################################################
This message (and any attachment) is intended only for the
recipient and may contain confidential and/or privileged
material. If you have received this in error, please contact the
sender and delete this message immediately. Disclosure, copying
or other action taken in respect of this email or in
reliance to it is prohibited.