Port 1080 probes from AOL

Suresh Ramasubramanian ops.lists at gmail.com
Fri Jun 1 03:58:26 UTC 2007

On 5/31/07, up at 3.am <up at 3.am> wrote:
> One of my virtual web host servers have been getting multiple probes to
> TCP port 1080 (socks) every day for months from AOL IP addresses.
> Is AOL known to be doing something relatively innocuous on that port?  I
> ask because I have portsentry null routing IP addresses that make probes
> like this.

If they're  [SOME HEX].ipt.aol.com rDNS'd IPs - those are AOL dialups,
so probably compromised / virus infected nodes

More information about the NANOG mailing list