Re: [Nolug] MS Blaster DDOS against the rest of us

From: Alex McKenzie <alex_at_boxchain.com>
Date: Tue, 19 Aug 2003 20:39:47 -0500
Message-ID: <3F42D163.1090202@boxchain.com>

Craig Jackson wrote:
> On Tuesday 19 August 2003 6:53 pm, Andrew S. Johnson wrote:
>
>>I was looking at the log on my SMC firewall, and I couldn't help
>>but notice that for the 174 or so entries that it can hold, that 169
>>of those are scans on port 135. In the 99 minutes that the log
>>currently holds, that's 17 scans per minute. DOH! Is my IP address
>>just a lucky honey-covered bullseye, or are y'all seeing the same
>>sort of activity? This is _WAY_ worse than average. Usually,
>>I'd see all sorts of scans, such MS SQL Slammer, NFS, telnet,
>>and the like. But this drowns them all out. If I could only trade
>>this for some telemarketing calls during dinner........
>>
>>Blasted in Luling,
>>
>>Andy
>>
>>Maybe if knock back the rum in the cupboard, I really be...
>>
>
> 64 blocked since July 26. Maybe I'm lucky.
>

177/179 in the last 42 1/2 minutes. Maybe I'm lucky.

-- 
Alex McKenzie     alex@boxchain.com     http://www.boxchain.com
___________________
Nolug mailing list
nolug@nolug.org
Received on 08/19/03

This archive was generated by hypermail 2.2.0 : 12/19/08 EST