Re: snort log entry question

From: Chris (cpollock_at_earthlink.net)
Date: 10/31/04


Date: Sun, 31 Oct 2004 17:14:48 GMT

Michael Heiming wrote:

>> On this one, why would Earthlink, my ISP, be doing a portscan on my
>> system? Could this just be a 'ping' from them?
>
>> Oct 25 23:42:17 cpollock snort[3860]: spp_portscan: PORTSCAN DETECTED to
>> port 41980 from 207.217.121.213 (STEALTH)
>
> Perhaps they are looking for vulnerable/already cracked/misused
> systems of their customers? Nothing to worry, you could drop them
> a mail and ask for reasons.
>
> Good luck
>

Thanks Michael, thats what I was looking for.

-- 
Chris
Registered Linux User 283774 http://counter.li.org
11:14am up 3 days, 18:44, 1 user, load average: 0.06, 0.04, 0.00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
There's nothing disgusting about it [the Companion].  It's just another
life form, that's all.  You get used to those things.
                -- McCoy, "Metamorphosis", stardate 3219.8
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Loading