First time I saw this one was two Friday's ago. Also reported by someone on the Nesuss list. Remarked that it had a lot of scans not in the nessus database.
In fact, each time it hit, it hit destination ip address 1500 times. Does not look like a 'worm' (not in dshield or mynetwatchman except for this target) and was not repeated (except now, different attack source) first attack was from the Bristol CT, Board of Education. Second (just now) from Belgium. mail.panatw.com [217.66.5.89] PAN OCEAN SHIPPING CO country: BE admin-c: RM4340-RIPE tech-c: DG119-RIPE status: ASSIGNED PA mnt-by: SEAGHA-MNT changed: [EMAIL PROTECTED] 20011205 See http://www.mynetwatchman.com/LID.asp?IID=13784474 for Belgium attack Full logs can be sent if needed. -- Michael Scheidell, CEO SECNAP Network Security, LLC Sales: 866-SECNAPNET / (1-866-732-6276) Main: 561-368-9561 / www.secnap.net Looking for a career in Internet security? http://www.secnap.net/employment/ - [EMAIL PROTECTED]: general discussions about Nessus. * To unsubscribe, send a mail to [EMAIL PROTECTED] with "unsubscribe nessus" in the body.
