Suspected nmap listing - am I under attack?
- From: fahimdxb@xxxxxxxxx
- Date: 18 Oct 2006 06:08:36 -0000
Did an nmap scan on my Cisco router from the outside world. Found the following output:
Interesting ports on *.*.*.1:
Not shown: 1676 closed ports
PORT STATE SERVICE
23/tcp filtered telnet
135/tcp filtered msrpc
1524/tcp filtered ingreslock
27665/tcp filtered Trinoo_Master
There is a Cisco PIX behind the inside interface though I ran nmap from across the serial.
What does the state "filtered" signify?
How can I be sure if I have been used as an agent for launching DDoS attack?
Please advise!!
---------------------------------------------------------------------------
This list is sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------
- Follow-Ups:
- Re: Suspected nmap listing - am I under attack?
- From: Arild Jensen
- Re: Suspected nmap listing - am I under attack?
- From: Zapotek
- Re: Suspected nmap listing - am I under attack?
- Prev by Date: Re: Using Web mail (hotmail, gmail, yahoo, etc) for Business mails
- Next by Date: Am I owned on port 27665
- Previous by thread: Distruted Intrusion Detection : how data is analyzed in current products
- Next by thread: Re: Suspected nmap listing - am I under attack?
- Index(es):
Relevant Pages
|