[ILUG] port scanning.. continued.
Donncha O Caoimh
donncha.ocaoimh at tradesignals.com
Tue Mar 14 11:21:57 GMT 2000
Now I'm getting very paranoid, mail their admins time I think.
Sascha Lucky Luck wrote:
> Thus spoke Donncha O Caoimh:
> > Mar 13 12:47:16 mail kernel: IP fw-in deny eth0 TCP 188.8.131.52:80
> > <MY_IP>:64982 L=44 S=0x00 I=32308 F=0x0000 T=51
> > Can anyone shed any light on what they're doing? (are they trying to get
> > at my httpd server on the last two lines?)
> This one is a connection FROM the web server on samanta.craghead.com TO your machine. Is there a matching _outgoing_ connection?
> I'm looking into the other connections, but yes it could be a portscan.
More information about the ILUG