port scanning activity going up recently?
"Ken Fox" <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Hi all - Has anyone else noticed a recent spike in port scan activity over the last few days? I've been seeing some interesting traffic where multiple source addresses are probing a number of the same high order destination ports from a small set of source ports with a number of different but specific packet sizes. e.g.: source port 3268 -> dest port 50572 packet size 48, 60, 64, and 52 egg: source port 3268 -> dest port 50592 packet size 48, 60, 64, and 52 Is there some botnet out there that I haven't heard about? thanks -- ken