> Has anyone seen this type of network scanning before? Addresses have been
> changed to protect the inocent and the guilty.
>
> Jan 30 11:14:41.922: %SEC-6-IPACCESSLOGP: list 111 denied tcp
> X.X.143.14(39620) -> X.X.211.227(80), 1 packet
>
> The node in question here has scanned a few other subnets looking for
> connections to port 80. Is this a recognised scanning program or something
> home grown?
>
It looks like someone is scanning for HTTPD.. Maybe someone is really anxious
to read your web pages :)
|
|