[nsp-sec] 1640/tcp puzzle.
Scott A. McIntyre
scott at xs4all.net
Mon Jun 30 01:44:03 EDT 2008
Hi teams,
A few weeks ago a handful of my customers started spewing packets to
one particular IP address on port 1640/tcp. This lit up my darknet,
but the problem went away. However, it's returned with a vengeance.
The destination is always 100.100.100.200:1640 and the src host count
has skyrocketed (from 1 or 2 per day to over 100). Does this
combination trigger anything in anyone's mind?
My default answer of "probably something p2p related" seems likely,
but if someone else has thoughts I'd appreciate it!
Cheers,
Scott A. McIntyre
XS4ALL Internet B.V.
More information about the nsp-security
mailing list