Re: snort log entry question
From: Chris (cpollock_at_earthlink.net)
Date: 10/31/04
- Next message: Neil Ellwood: "Re: iptables"
- Next in thread: Chris: "Re: snort log entry question"
- Maybe reply: Chris: "Re: snort log entry question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 31 Oct 2004 17:14:48 GMT
Michael Heiming wrote:
>> On this one, why would Earthlink, my ISP, be doing a portscan on my
>> system? Could this just be a 'ping' from them?
>
>> Oct 25 23:42:17 cpollock snort[3860]: spp_portscan: PORTSCAN DETECTED to
>> port 41980 from 207.217.121.213 (STEALTH)
>
> Perhaps they are looking for vulnerable/already cracked/misused
> systems of their customers? Nothing to worry, you could drop them
> a mail and ask for reasons.
>
> Good luck
>
Thanks Michael, thats what I was looking for.
-- Chris Registered Linux User 283774 http://counter.li.org 11:14am up 3 days, 18:44, 1 user, load average: 0.06, 0.04, 0.00 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ There's nothing disgusting about it [the Companion]. It's just another life form, that's all. You get used to those things. -- McCoy, "Metamorphosis", stardate 3219.8 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Next message: Neil Ellwood: "Re: iptables"
- Next in thread: Chris: "Re: snort log entry question"
- Maybe reply: Chris: "Re: snort log entry question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Loading