On 08/10/10 10:43 PM, Ned Slider wrote: > After moving ssh to an alternative port, I typically see around 3 probes > a day on port 22 in my firewall logs. How many are you seeing? If it's > significantly more than that, why? some subnets seem to get hit alot more often by the drones. bad randomizers? lists of preferred scan targets based on prior vulnerable targets? probably a mix.