> My newly polished-up Debian firewall is logging so many connection > attempts to port 80 that I truly can't believe it. All different
as another guy pointed it is likely code red, or code red II. I have logged almost 10,000 attempts today on one of my networks which runs on a DSL line. 2 other networks that run on t1s have ~25 hits combined. so its clear its affecting dsl/cable modems more then others. i suggest using snort and demarc on your firewall if your not using some kind of packet sniffer already. demarc is available at demarc.org. free for non commercial use. for commercial use its about $900 for up to 8 stations. well worth it. it can be difficult to setup though if your not used to playing with source code programs. demarc is available at demarc.org snort is available at snort.org nate