[NTLUG:Discuss] ICMP virus was: ICMP connection request to port2048
Paul Ingendorf
pauldy at wantek.net
Fri Aug 22 08:24:13 CDT 2003
What you are seeing there isn't a port but the icmp packet identifier. Your
seeing the worm looking for targets nothing more. Well your port scanners
were in there also.
-----Original Message-----
From: discuss-bounces at ntlug.org [mailto:discuss-bounces at ntlug.org]On
Behalf Of Tom Tumelty
Sent: Thursday, August 21, 2003 8:43 PM
To: NTLUG Discussion List
Subject: RE: [NTLUG:Discuss] ICMP virus was: ICMP connection request to
port2048
I use Agnitum outpost firewall and this is a sample of
what i have been seeing in my firewall log the last
few days. I apologize for the poor format :
Date/Time Attack Type
8/21/2003 8:36:02 PM Connection request
IP Address Scan Port Details
65.148.176.236 ICMP(2048)
8/21/2003 8:35:57 PM Connection request 65.148.107.250
ICMP(2048)
8/21/2003 8:35:39 PM Connection request 65.150.137.9
More information about the Discuss
mailing list