Fairly rude surprise in logs this AM -- possible DoS attempt?

Wolfgang S. Rupprecht wolfgang+gnus-baylisa at dailyplanet.dontspam.wsrcc.com
Mon Jan 19 13:14:18 PST 2004


david at catwhisker.org (David Wolfskill) writes:
> This morning, the usual quota was augmented by 83610 lines that
> were created during the period 13:03:28 - 16:47:15 yesterday (local
> time), each from 62.58.50.220, dsbl.zonnet.nl.  (Note that there
> are certain packets that I drop silently.)

Could it be related to the new "bagel" microsoft-virus?  The following
article mentions that it tries to connect to remote web sites and also
to port 6667/tcp.

 http://www.theinquirer.net/?article=13697

> Anyone else have similar experiences of late?

Nothing that far out of the ordinary.  Just the usual 500 per day of
137/udp and a few dozen random ports.

-wolfgang
-- 
Wolfgang S. Rupprecht 		     http://www.wsrcc.com/wolfgang/
       The above "From:" address is valid.  Don't mess with it.
Gripe to your senators about spam:  http://www.wsrcc.com/spam/senators.html




More information about the Baylisa mailing list