Noticed some neat activity in my firewall logs lately: distributed port scanning.
Uncategorized
1
Posts
1
Posters
0
Views
-
Noticed some neat activity in my firewall logs lately: distributed port scanning. A slow batch-sequential poke at every port spread across dozens of source IPs in what I assume is an attempt to evade scan-aware blocks before the scan is completed. If you're looking at the logs as a raw time-ordered list, it might never be apparent what's happening. If you start correlating the sources with ports over time, though, it pops out of the data.
-
undefined Oblomov shared this topic on