[ILUG] port scanning.. continued.

Donncha O Caoimh donncha.ocaoimh at tradesignals.com
Tue Mar 14 11:21:57 GMT 2000


Now I'm getting very paranoid, mail their admins time I think.

Donncha.


Sascha Lucky Luck wrote:
> 
> Thus spoke Donncha O Caoimh:
> > Mar 13 12:47:16 mail kernel: IP fw-in deny eth0 TCP 216.15.159.194:80
> > <MY_IP>:64982 L=44 S=0x00 I=32308 F=0x0000 T=51
> > Can anyone shed any light on what they're doing? (are they trying to get
> > at my httpd server on the last two lines?)
> 
> This one is a connection FROM the web server on samanta.craghead.com TO your machine. Is there a matching _outgoing_ connection?
> 
> I'm looking into the other connections, but yes it could be a portscan.




More information about the ILUG mailing list