[Snort-users] Win* machines - port 139 scans

H Carvey keydet89 at ...131...
Sun Oct 1 16:21:17 EDT 2000


> We got the exact scans everyday from numerous
> bellsouth subnets. I pasted some of the captures
into
> an e-mail to the abuse address and sent it off with
> an explanation. Their response was that they
couldn't
> do anything to help me without timezone information.
> In other words, they didn't want to do anything.

Hhhmm...w/o portions of the scans I can't say for
sure...but it sounds like they wanted to know your
timezone b/c they use DHCP for dial-up, and the
timezone info would be the only way they have of
correlating the time of the scan to the user who had
the IP address at the time.

...just a thought.  Would take too much for you to
just send back "EST" or whatever...

C

__________________________________________________
Do You Yahoo!?
Yahoo! Photos - 35mm Quality Prints, Now Get 15 Free!
http://photos.yahoo.com/



More information about the Snort-users mailing list