RE: New spam-probing wave?

From: Danny (Danny@drexel.edu)
Date: 01/25/03

  • Next message: slswick@aep.com: "Re: Increased activity on UDP/1434"
    From: Danny <Danny@drexel.edu>
    To: 'Jeff Kell' <jeff-kell@utc.edu>, "'patrick.oonk@pine.nl'" <patrick.oonk@pine.nl>
    Date: Sat, 25 Jan 2003 16:26:22 -0500
    
    

    |>The worst offender is 138.121.23/24, a newer source is 200.30.203.160.
    |>Others come and go, but the first one has been at it since before
    |>Christmas.
    |>
    |>Jeff
    |>
    |>--------------------------------------------------------------------------
    |>--
    |>This list is provided by the SecurityFocus ARIS analyzer service.
    |>For more information on this free incident handling, management
    |>and tracking system please see: http://aris.securityfocus.com

    We've been seeing these guys bang away at our networks too. Emails to abuse contacts and upstream providers, obviously doesn't seem to do a thing.

    Cheers
    Danny
    Network Security Engineer
    Drexel University

    Digital ID Print: 874f 1b77 470f 0b10 126e d8d2 c3a3 d52a 24ab 73c3
    PGP Print: C6AD B205 E3C6 38AB 0164 6604 66F5 CCFC F4ED F1E0
    PGP Key: http://akasha.irt.drexel.edu/danny.asc

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • RE: PDL anti-spam blacklist
      ... >:> This list is provided by the SecurityFocus ARIS analyzer service. ... >:> For more information on this free incident handling, management ... >:> and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)
    • Re: Linux Kernel Exploits / ABFrag
      ... There have been lots of rumors ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)
    • Re: Bind 9.2.X exploit???
      ... >>> This list is provided by the SecurityFocus ARIS analyzer service. ... >>> For more information on this free incident handling, management ... >>> and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)
    • RE: "Code Red" worm questions
      ... but from other research we think the worm only tries to attack ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: ...
      (Incidents)
    • RE: Ip spoof from 0.0.0.0
      ... > This list is provided by the SecurityFocus ARIS analyzer service. ... For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)