From: Gerard Gorman (g.gorman at domain ic.ac.uk)
Date: Mon 20 Aug 2001 - 19:11:49 IST
I was just lookin at some funny in my long. I'm getting a lot of
snooping on my ftp port (tcp-wrappers are dropping everything ;). But
all the connections come in threes!
eg.
secure:Aug 20 04:15:52 moby in.ftpd[10696]: refused connect from
216.45.78.231
secure:Aug 20 04:15:52 moby in.ftpd[10697]: refused connect from
216.45.78.231
secure:Aug 20 04:15:52 moby in.ftpd[10698]: refused connect from
216.45.78.231
Because there are so many of these, I'm assuming that it's a common
script that's being used. Does anyone reconise this? I'd like to get a
hold of the script to make double sure it isn't being successfull on
some other port.
Cheers,
g
This archive was generated by hypermail 2.1.6 : Thu 06 Feb 2003 - 13:11:44 GMT