snort log entry question

From: Chris (cpollock_at_earthlink.net)
Date: 10/31/04


Date: Sat, 30 Oct 2004 22:17:38 GMT

I've been using snort for a couple of months now and although there have
been very few log entries those that are there I seem to have a hard time
understanding what they mean. I asked the below question in the
snort-users list awhile back but never received a reply, maybe it was just
too dumb of a question. Anyway, if anyone can explain what the two entries
mean or point me to a link(s) that do I'd appreciate it.

Oct 26 09:00:20 cpollock snort[3860]: [1:402:4] ICMP Destination Unreachable
(Port Unreachable) [Classification: Misc activity] [Priority: 3]: {ICMP}
217.160.253.84 -> 192.168.1.2

On this one, why would Earthlink, my ISP, be doing a portscan on my system?
Could this just be a 'ping' from them?

Oct 25 23:42:17 cpollock snort[3860]: spp_portscan: PORTSCAN DETECTED to
port 41980 from 207.217.121.213 (STEALTH)

Thanks to all in advance for any help

-- 
Chris


Relevant Pages

  • Re: snort log entry question
    ... In comp.os.linux.security Chris: ... > I've been using snort for a couple of months now and although there have ... > been very few log entries those that are there I seem to have a hard time ... Nothing to worry, you could drop them ...
    (comp.os.linux.security)
  • Re: Dealing with portscans
    ... Most of this sort of port scanning is automated by infected machines ... Mostly Useless log entries as pointed out earlier. ... I'm currently using) render the above redundant, ...
    (freebsd-questions)
  • Re: Connection refused, httptunnel?
    ... > I am trying to access my home machine from work - it works fine at ... > listen on port 80 to avoid work firewall issues: ... connection attemps. ... I see no log entries of this either. ...
    (comp.security.ssh)
  • Denied UDP packet from LAN port 4654 to router 1900
    ... hundreds of log entries for "12/03/2002 15:37:30.064 Denied UDP packet from ... They all come from the same Windows XP Professional computer on port 4654 ... Our domain is an NT4 domain. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Device continuously prompts for credentials during Sync
    ... > few other requests to port 80, while it's executing on the server. ... my default web site on this box is not on port 80! ... > so I rectified this and now I do get additional log entries, however, the ... why does the first request fail with a 503? ...
    (microsoft.public.pocketpc.activesync)