
9 Sep
2001
9 Sep
'01
4:59 p.m.
Has anyone seen a dramatic increase in FTP probes/scans/bad stuff from certain IP blocks in Taiwan or China? Specifically, 211/8, 61/8, and 202/7. I'm logging over 7500 probes/hr right now. Is there a new exploit out or something?
Another network just surfaced: 210.82/15
I am getting lots of port 80'ish scans from those IP ranges. and a few port 139, but I have not seen a port 21 (FTP) scan from anyone in the last 30 minutes... while monitoring a /19 and a /20 locally.