*SHORT* summary of some of the attacks against us for Sep 2004 Just too many scans and not enough time to keep the list up all the time so... some of the more intresting scans/attacks, or 1 day samples are here year - time EASTERN source_ip[:port] (dns name, if any) attack/scan/notes 2003/09/01-11:37:11 202.64.28.81 (Hong Kong) scan net for port 22, try login as root 2004/09/04-10:00:20 80.116.201.89 (host89-201.pool80116.interbusiness.it.) scannet for port 32771 2004/09/04-10:00:19 80.116.201.89 (host89-201.pool80116.interbusiness.it.) scan net for portmap port for prog=100083,lprog=100221,prog=100232 2004/09/05-06:36:40 62.138.46.106 (HighwayOne GmbH,Muenchen,DE) login to unix as guest/guest, root/root 2004/09/19-19:19:13 61.166.155.162 (chinanet..) scan unix machines, try ssh to login as root 2004/09/19-14:35:00 221.151.112.79 (korea) scan unix machines, try ssh to login as root, test, admin,... 2004/09/21-14:34:46 221.151.112.79 (korea) scan unix machines, try ssh to login as root,.. 2004/09/22-15:57:13 203.71.62.9 (Taiwan Academic Network) scan unix machines, try ssh to login as root 2004/09/24-20:49:34.50 211.112.137.236 (Korea crap) scan net &buff overflow attack on port 6112 - dtspc 2004/09/26-13:31:46. 209.213.0.21 (focus.bcn.net.-MA,USA) scannet port 111,