code red virus?

j plug-discuss@lists.plug.phoenix.az.us
Wed, 12 Jun 2002 06:55:57 -0700


By "hits" I meant attempts to negotiate the firewall as per  the intrusion 
detection logs. Sorry if I was not clear.

On Tuesday 11 June 2002 13:32, you wrote:
> How are you defining "hits"?
>
>
> On Wed, Jun 12, 2002 at 12:18:36AM -0700, User wrote:
>  Lately we have noticed that our friendly firewall is taking hits  from
>  what seems to be Russia. At least today it seems to be Russia.
>  Novoisvirsk, it seems like, according to traceroute.
>  I don't know a whole lot about probes like this but am thankful to you
>  folks for your guidance with regard to firewalls.
>
>  Is there something that we can do with regard to this type of thing?
>  Maybe, just track them down for fun. Where would be a good place to
>  start reading about this sort of thing.
>
>  We trace routed them throught 25 hops to 217.70.107.151
>
>  p151.rnttu.sinor.ru was the last hop on the list.
>
>  Thank you
>  Roger
>
>  ________________________________________________
>  See http://PLUG.phoenix.az.us/navigator-mail.shtml if your mail doesn't
> post to the list quickly and you use Netscape to write mail.
>
>  PLUG-discuss mailing list  -  PLUG-discuss@lists.plug.phoenix.az.us
>  http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss
> ________________________________________________
> See http://PLUG.phoenix.az.us/navigator-mail.shtml if your mail doesn't
> post to the list quickly and you use Netscape to write mail.
>
> PLUG-discuss mailing list  -  PLUG-discuss@lists.plug.phoenix.az.us
> http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss