"ynotssor" <ynotssor@xxxxxxxxxxx> writes:

"Harry Putnam" <reader@xxxxxxxxxxx> wrote in message

I've nmapped a host hitting my port 22 repeatedly and see this:

22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop3
111/tcp open rpcbind
135/tcp filtered msrpc
143/tcp open imap
443/tcp open https
445/tcp filtered microsoft-ds
993/tcp open imaps
995/tcp open pop3s
3306/tcp open mysql
10000/tcp open snet-sensor-mgmt
31337/tcp open Elite

Is this a zombie that doesn't now its controlled with a backdoor at
31337/tcp open Elite or just some sort of comeon filter or

Port 31337 is open; nmap (in the absence of -sV) has no idea what process is
bound to that particular port and is merely reporting the entry from the
nmap-services file.

So you think that by port scanning their machine that you are any different
from them and what they are doing?

Port scanning is not and indication of something bad always.
I did't port scan them as a retaliation as you seem to imply.

I posted here because I'm wondering if I need to contact that admin
and let them know they have a back door, and there machine is being
used by somebody to cladestinely portscan and otherwise prepare for
illegal breakins.

My portscan was not clandestine... I will answer for it to any and all

