Port 1080 probes from AOL
ops.lists at gmail.com
Fri Jun 1 03:58:26 UTC 2007
On 5/31/07, up at 3.am <up at 3.am> wrote:
> One of my virtual web host servers have been getting multiple probes to
> TCP port 1080 (socks) every day for months from AOL IP addresses.
> Is AOL known to be doing something relatively innocuous on that port? I
> ask because I have portsentry null routing IP addresses that make probes
> like this.
If they're [SOME HEX].ipt.aol.com rDNS'd IPs - those are AOL dialups,
so probably compromised / virus infected nodes
More information about the NANOG