View Single Post
Old 12-11-2003, 08:12 PM   #5 (permalink)
charliex
Junkie
 
Location: North Hollywood
1.3.3.7 is going to be a forged IP address,, i would say is NIMDA since 1.3.3.7 is the one it attempts first.


the rest are either port scanners, worms or search robots

62.49.122.2 - mailgate.ferrodesign.co.uk , probably a smtp server, maybes its an open proxy thats being abused

67.20.204.16 co-briar-u1-c4h-16.clspco.adelphia.net some end user whos either scanning or has a worm or virus infection

209.218.69.253 - proxyscan.freenode.net someones/thing is scanning you for open proxies, check you dont have one

216.194.70.12 proxy.scanner.for.irc.mircx.com its becoming clearer whats going on, i think, are you using IRC ? on different networks, their proxyscanners are checking your ip for an open proxy when you connect. (or someone else is somehow)

IRC is a haven for crackers sometimes, so make sure your firewalls are working especially if you don't know the irc network very well , the proxy scanners are a normal part of most irc servers, and they'd likely kill or k/gline you if they detected one on your system (if its you running irc on other servers)

charliex is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76