First time I saw this one was two Friday's ago.
Also reported by someone on the Nesuss list.
Remarked that it had a lot of scans not in the nessus database.

In fact, each time it hit, it hit destination ip address 1500 times.
Does not look like a 'worm' (not in dshield or mynetwatchman except for
this target) and was not repeated (except now, different attack source)

first attack was from the Bristol CT, Board of Education.

Second (just now) from Belgium. mail.panatw.com [217.66.5.89]

PAN OCEAN SHIPPING CO
country:      BE
admin-c:      RM4340-RIPE
tech-c:       DG119-RIPE
status:       ASSIGNED PA
mnt-by:       SEAGHA-MNT
changed:      [EMAIL PROTECTED] 20011205

See http://www.mynetwatchman.com/LID.asp?IID=13784474 for Belgium attack

Full logs can be sent if needed.

-- 
Michael Scheidell, CEO
SECNAP Network Security, LLC 
Sales: 866-SECNAPNET / (1-866-732-6276)
Main: 561-368-9561 / www.secnap.net
Looking for a career in Internet security?
http://www.secnap.net/employment/
-
[EMAIL PROTECTED]: general discussions about Nessus.
* To unsubscribe, send a mail to [EMAIL PROTECTED] with
"unsubscribe nessus" in the body.

Reply via email to