*SHORT* summary of some of the attacks against us for Jul. 2008 Just too many scans and not enough time to keep the list up all the time so... some of the more intresting/annoying scans/attacks, or 1 day samples are here year - time EASTERN source_ip[:port] (dns name, if any) attack/scan/notes 2008/07/29-04:01:28 195.5.117.239 (s39.esthost.eu.) tried ftp login of prasad passwd prasad on bobcat 2008/07/28-16:48:43 195.5.117.239 (s39.esthost.eu.) tried ftp login of af641 passwd af641 on freenet 2008/07/28-21:47:56 195.5.117.239 (s39.esthost.eu.) tried ftp login of ag148 passd ag148 on freenet 2008/07/29-01:47:56 195.5.117.239 (s39.esthost.eu.) tried ftp login of ag148 passd ag148 on freenet 2008/07/29-13:14:35 195.5.117.239 (s39.esthost.eu.) tried ftp login of bosscher passwd bosscher on bobcat 2008/07/29-22:41:15 195.5.117.239 (s39.esthost.eu.) tried ftp login of water200 passwd water200 on bobcat 2008/07/30-19:49:45 195.5.117.239 (s39.esthost.eu.) tried ftp login of voters passwd voters on freenet 2008/07/30-21:01:31 195.5.117.239 (s39.esthost.eu.) tried ftp login of marling passwd marling on ace 2008/07/31-07:02:37 195.5.117.239 (s39.esthost.eu.) tried ftp login of changliu passwd changliu on ace 2008/08/02-03:20:18 195.5.117.239 (s39.esthost.eu.) tried ftp login of ad814 passwd ad814 on freenet 2008/08/02-09:45:18 195.5.117.239 (s39.esthost.eu.) tried ftp login ond same passwd on ace 2008/08/03-04:25:00 195.5.117.239 (s39.esthost.eu.) tried ftp login ond same passwd on freenet 2008/08/03-23:06:46 195.5.117.239 (s39.esthost.eu.) tried ftp login ond same passwd on freenet 2008/08/04-00:00:00 195.5.117.239 (s39.esthost.eu.) is continuous. yawn. 2008/08/04-00:00:00 194.199.16.252 (test16252.inrialpes.fr.) tries 5 dns lookups/day on non-public dns server for names like 'e3ee0064cea9fa6bd52ce1e050e30505.test.blackholedns.net/A/IN'. No other connections to us though..