[NTLUG:Discuss] ICMP virus was: ICMP connection request to port2048

Paul Ingendorf pauldy at wantek.net
Fri Aug 22 08:24:13 CDT 2003


What you are seeing there isn't a port but the icmp packet identifier.  Your
seeing the worm looking for targets nothing more.  Well your port scanners
were in there also.

-----Original Message-----
From: discuss-bounces at ntlug.org [mailto:discuss-bounces at ntlug.org]On
Behalf Of Tom Tumelty
Sent: Thursday, August 21, 2003 8:43 PM
To: NTLUG Discussion List
Subject: RE: [NTLUG:Discuss] ICMP virus was: ICMP connection request to
port2048


I use Agnitum outpost firewall and this is a sample of
what i have been seeing in my firewall log the last
few days. I apologize for the poor format :

Date/Time                  Attack Type
8/21/2003 8:36:02 PM	Connection request
IP Address        Scan Port Details
65.148.176.236	ICMP(2048)

8/21/2003 8:35:57 PM	Connection request	65.148.107.250
ICMP(2048)

8/21/2003 8:35:39 PM	Connection request	65.150.137.9




More information about the Discuss mailing list