[Snort-users] Proxy Scanner?

Sylar, John JSylar at ...5426...
Fri Dec 20 06:52:13 EST 2002


Lately, I'm seeing this sort of scan alot, from assorted netblocks. Doesn't
seem to correlate to the Incidents site.
While the source port is not always 0, the destination ports are always the
same, in the same order.
Does anyone know what tool this might be? Or have some pointers to
references for reading?
Dec 19 18:39:14 their.i.p.addr:0 -> my.i.p.addr:1080 SYN ******S*
Dec 19 18:39:14 their.i.p.addr:0 -> my.i.p.addr:3128 SYN ******S*
Dec 19 18:39:14 their.i.p.addr:0 -> my.i.p.addr:8000 SYN ******S*
Dec 19 18:39:14 their.i.p.addr:0 -> my.i.p.addr:80 SYN ******S*
Dec 19 18:39:14 their.i.p.addr:0 -> my.i.p.addr:8080 SYN ******S*
Thanks and best regards,
Sam




More information about the Snort-users mailing list