strange firewall log

From: keith (keith@w-o-i.com)
Date: 02/20/02


From: keith@w-o-i.com (keith)
Date: 19 Feb 2002 20:47:43 -0800

Hi,

I have an ipchains firewall running on my Redhat 6.2 server. I got
this in my firewall log. Can Anyone tell me what this means.

Feb 19 15:23:18 | output DENY eth1 src=192.168.0.1:139
dest=1.0.0.1:1030 (#14)

Somebody from our server is going to a reserved IP address(1.0.0.1).
Is my machine hacked. Is there a trojan.
Is it any good to put an IDS once I have been hacked.
Please help me.

Thanks

Regards,
Keith



Relevant Pages