All I can say is the person surfing from 207.59.75.2 is the guilty party involved. The Netblock is owned by
American Saftey Insurance AMERICAN-SAFTEY-INSURANCE (NET-207-59-75-0-1) 207.59.75.0 - 207.59.75.15Of particular note
Interesting ports on 207.59.75.2:
(The 1214 ports scanned but not shown below are in state: closed)
PORT STATE SERVICE
135/tcp filtered msrpc
136/tcp filtered profile
137/tcp filtered netbios-ns
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
1503/tcp filtered imtc-mcs
So it appears to be a M$ NT4/2K/XP/2K3 machine.
There are quite a few other machines on that network... that umm aren't exactly... well.
Scott, If you could please blank this out. And if you could lock this account.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @
iwetheyNo matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]Here is an example: [link|http://www.greymagic.com/security/advisories/gm001-ie/|Executing arbitrary commands without Active Scripting or ActiveX when using Windows]