0 Replies Latest reply on May 11, 2010 4:10 PM by protector

    Odd traffic on telnet port 23

    protector

      I am posting this to ask if there is anyone who has encountered any rootkits or viruses trying to talk on port 23.  VSE didn't capture anything, the rootkit utility from mcafee didn't capture anything, our packet capture utility (infinistream) didn't capture anything, but our Firewall did stop the traffic on port 23.  We got about 1000 hits within 1 hour.  It was trying to hit IP address 192.165.55.106 which is registered with RIPE in Amsterdam. 

       

      Has anyone seen anything similar?