Hi,
From past 1 week, I'm noticing a large number of port scans on my boxes from mainly chinese ip's(Us, uk, russian ip's are there but limited numbers only). I did block several chinese ip blocks.
if at all they wanted to ddos my box, they could easily take it down. But, they are only port scanning(from around 2-5 ip's a minute), probably to find open unsecured ports/exploits.
Are they searching for larger number of unsecured servers, to have the next dooms day on the net and having a new ddos target set?