Re: false portscan alarm
- From: Bit Twister <BitTwister@xxxxxxxxxxxxxxxx>
- Date: Tue, 17 Oct 2006 09:58:38 -0500
On Tue, 17 Oct 2006 13:23:40 +0200, mikahan wrote:
I receive regulary notification from my personall firewall about port
scanning make by www.microsoft.com. This is the information from my log
no, microsoft.com is 207.46.130.108/207.46.250.119
2006-09-12 09:20 port scan from 207.46.18.30 TCP (1700, 1730, 1734,
1733, 1168, 1165)
2006-09-12 09:20 port scan from 207.46.18.30 TCP (2054, 2060, 2056,
2052, 2058, 2050)
207.46.18.30 is wwwbaytest5.microsoft.com
Does it mean taha microsoft try to hack me ? :-)
What is the reason of that treffic ?
Looking up those ports at
http://isc.sans.org/port_details.php?port=1730 (example)
would seem to indicate wwwbaytest5.microsoft.com has some malware
hunting for more exploitable systems.
.
- Follow-Ups:
- Re: false portscan alarm
- From: Spack
- Re: false portscan alarm
- References:
- false portscan alarm
- From: mikahan
- false portscan alarm
- Prev by Date: false portscan alarm
- Next by Date: Re: Zone Alarm Pro on server denying client access to 'Net from client laptop
- Previous by thread: false portscan alarm
- Next by thread: Re: false portscan alarm
- Index(es):
Relevant Pages
|