|
Strange ICMP: msg#00052security.intrusions
Hi, I am detecting an increased amount of ICMP Ping traffic. The strange thing is that there are several sources that are hitting us about 1000 times a week. All of these sources have a last octet of some form of 36 and 37. 63.163.102.36 & 37 216.34.77.36 & 37 64.209.232.36 & 37 61.213.167.236 & 237 193.95.144.136 & 137 These are from different ISPs and in a couple countries. The destination is on a Cable Modem that has no inbound access. It's not causing an issue, it's just anomalous. Anyone else seeing this kind of traffic, or have any ideas on the origin? Ron Shuck, CISSP, GCIA, CCSE - Managing Consultant Buchanan Associates - A Technology Company in the People Business _______________________________________________ Intrusions mailing list Intrusions@xxxxxxxxxxxxxx http://www.dshield.org/mailman/listinfo/intrusions |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | [LOGS] Summary of large-scale portscanning detects: 00052, Ken . Connelly |
|---|---|
| Next by Date: | AW: Strange ICMP: 00052, "Seemüller, Christian" |
| Previous by Thread: | LOGS: GIAC GCIA Version 3.4 Practical Detect Jose Faiali: 00052, José Faial |
| Next by Thread: | Re: Strange ICMP: 00052, Heather Flanagan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |