Re: Cisco vulnerability scanning increase
Joshua Hamor <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
[email protected] wrote: >We recently picked up a spike in TCP 80 scanning against one of our netblocks. > >Looking at the payload, it appears to be a Cisco vulnerability scanner. > > /level/16/exec/-///pwd > >Numerous random source IP's across various netblocks, makes it appear to be bot related potentially. Anyone else seeing this type of activity? > > > Absolutely. I was wondering what it was myself. Thanks for the clue. My error log is filled with that and the awstats scanning.