At least one attacker who queries IDENT servers is using the ports straight out of the example in Wikipedia.
Early results are not promising. I've had a handful of HEAD requests in the past day. Only 2 appear legitimate, in that they hit genuine page URLs. The others were attempts to exploit WordPress vulnerabilities.