From: Tomas L. Byrnes (no email)
Date: Thu Mar 06 2008 - 19:22:09 EST
Have you queried the DShield database for the hosts you are seeing?
http://www.dshield.org/ipinfo.html?ip= add the IP after the =
> -----Original Message-----
> From: [mailto:] On
> Behalf Of Rich Sena
> Sent: Thursday, March 06, 2008 12:02 PM
> To: NANOG
> Subject: Scan traffic from 121.8.0.0/16
>
>
> Anyone seeing anything similar - trying to determine if this
> is spoofed etc...
>
> --
> Rich Sena -
> ThickNET Consulting
> "On the way to understanding; you understand, and forget."
>
>
|
|
|