Re: Scans for telnetd on DNS servers.

"Pavel Kankovsky" <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
On Thu, 9 Mar 2006, Alex wrote:

> Could this be a SSH scan by some stupid script kiddie that mistook the
> telnet port# for that of SSH?

It would have to be a kiddie with an army of zombies at his (or her) 
disposal. The probes came from hundreds (if not thousands) of different
IPs and a small random sample I checked was able to finish the TCP 3-way 
handshake (and read a server greeting and disconnect) when it probed an 
address where a telnet server was listening and accessible.

--Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.