[nsp-sec] Odd "attack" traffic

Chris Morrow morrowc at ops-netman.net
Tue Dec 28 22:02:57 EST 2010


On 12/28/10 9:59 PM, Kevin Oberman wrote:
> ----------- nsp-security Confidential --------
> 
> Mike and Joel,
> 
> This makes some sense. It looks like my system has been entered in some
> list of servers and various systems keep trying to connect. The system
> is a FreeBSD box that I am quite sure is not and never has had that port
> open.
> 
> I'll see if the stuff I'm packets I'm getting look like what you
> reported. 

keep in mind that some of the (baytsp for one) RIAA/MPAA shills will
spew this sort of traffic over ip ranges in hopes that they get replies
and this can send subpoenas toward the ip-owners :(

no, I'm not bitter about getting ~1k of these to a darknet... and having
to visit the corp-council's offices to explain.

-chris



More information about the nsp-security mailing list