*SHORT* summary of some of the attacks against us for Aug. 2003 Just too many scans and not enough time to keep the list up all the time so... some of the more intresting scans/attacks, or 1 day samples are here year - time EASTERN source_ip[:port] (dns name, if any) attack/scan/notes 2003/08/08-16:03:53.08 132.235.196.143 (CNS at OU...) scan 132.235.1.39 port 13 22 79 111 4045 6000 6112 32771 32772 32773 32774 2003/08/08-12:19:03.27 63.139.53.44 (CPE000255706ae4-CM0080378586c7.cpe.net.cable.rogers.com) scannet for port 111 2003/08/13-03:21:28 81.99.201.24 (public3-addl1-5-cust24.hers.broadband.ntl.com) try multiple time to ftp into prime as root 2003/08/12-05:35:24.44 217.233.228.70 (pointepD9E9E446.dip.t-dialin.net) heavy scan of net for port 80 2003/08/13-03:20:22.84 81.99.201.24 (public3-addl1-5-cust24.hers.broadband.ntl.com) scan net for port 69 2003/08/17-15:06:46.70 213.177.133.240 (adsl-133-240.wanadoo.be) try to create dirs on ftp server using anon logins. 2003/08/21-13:43:47.62 80.180.158.40 (host40-158.pool80180.interbusiness.it) telnet buff overflow attacks 2003/08/22-13:47:23.02 67.162.197.56 (c-67-162-197-56.client.comcast.net) portscan multiple hosts. 2003/08/23-06:03:01.64 61.139.60.117 (CHINANET Sichuan province network) scan net, multiple ip/port combos. 2003/08/22-17:42:18.37 63.204.137.156 (adsl-63-204-137-156.dsl.snfc21.pacbell.net) scannet for port 4000