• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

410 incidients today of hitting my firewall

Chunkee

Lifer
Tues, 01/11/2005 05:34:47 - TCP connection dropped - Source:65.6.2.167, 19557, WAN - Destination:xx.xx.xx.x, 24932, LAN - 'Establish TCP Abnormally'
End of Log ----------

410 times in about 16 hours.

good grief

jC
 
That's really interesting. My firewall has been picking up tons of abnormal TCP packets from my ISP. Granted it's on port 0 which according to some people on nmap is used for OS fingerprinting.
 
Originally posted by: Chunkee
what is usual cause of these? Unknown attacks from a virus or just some ahole trying to be a butt?

jC

Well in my case the offending IP address is 69.24.160.1. It looks a user block of IPs for the ISP according to arin.net.
 
Only 410 hits? When the Sasser worm and other variants are out there I get that many in an hour. I just smile at the fact that I have a firewall doing its job. 🙂
 
I wouldn't worry about it as long as your firewall is blocking it and its not causing any service disruptions.

410 in 16hrs might seem like a lot, but it isnt.

When Blaster was released, we had over 100,000 scans across all of our blocks in 12 hours.
 
Back
Top