RE: SNMP worm?
Frank Knobbe <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <1130400421.2772.4.camel@localhost> |
On Wed, 2005-10-26 at 21:52 -0400, Robert MacDonald wrote: > None here (yet). Possible a contractor or vendor showing off network > solution-wares? Does it appear to be polling sequentially or > randomly? Is it looking through particular subnets? Is it possibly a > new printer(s) that have been plugged in or gone wild? Another possibility is a misconfigured network management station. I remember one incident in the past where a certain subnet got routinely scanned from one particular box, which was named like "netmon.noc.company.com". We notified the contact of that domain and kept an eye on it. Eventually the flood stopped, so perhaps someone noticed that a netmask was entered wrong :) What was that saying about not attributing malice to something that can be explained with stupidity? :) Cheers, Frank
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQBDYIqlwBQKb2zelzoRAqgEAKCycIRub+tFpdmAbDKo6cwqlV+hrACfc9DE 6Y8vff4cqwFmd5I2Z4tdd1I= =eKG5 -----END PGP SIGNATURE-----