On Sun, 2003-08-17 at 16:27, Wolfgang Bornath wrote: > Hi, > > I installed a new WLAN router/access point and after configuring the > beast I looked at the logs in the router after a couple of hours. > > I found more than 100 entries (during 3 hours) like: > > Time Message Source Destination Note > ------------------------------------------------------------------------ > 01:01:45 Dropped TCP 211.74.178.73:1342 x.x.x.x:445 Rule: > packetfrom WAN default deny > > The sources are mostly the same (6 or 7 different), all trying my IP > (x.x.x.x) and several different ports: > > 445, 135, 1839, 2536, etc. > > Is this normal attack attempts or results of the infamous worm? > BTW: I'm not using any donkeys or such kiddie stuff. > > wobo > Wobo they are the worm and it's various forms. Since it shuts down the box every couple of minutes you'd think this thing would eventually kill all the infected ones and make it so impossible to use the box people would have to patch.
James
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com