- From: "marquisaj" <marquisaj@xxxxxxxxx>
- Date: 22 Dec 2006 12:29:14 -0800
I was notified by a network administrator that one of our servers is
running a full port scan on their network. How can I detect how this is
being done on our server. They sent a log that shows the Time Stamp,
Attack, Source IP, and Destination IP.
The server is a Windows 2000 server with IIS 5.0.
- Prev by Date: Re: Unknown svchost.exe DNS port 53 network activity
- Next by Date: Re: Enable file auditing on many servers
- Previous by thread: Re: Unknown svchost.exe DNS port 53 network activity
- Next by thread: Re: Port Scanning