[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Hmm




Smells like someone with a Windoze box attempting to connect to your system. I get quite a lot of this traffic on my web server (and silently deny it). What services do you have running on your (presumed NAT'ed) system 10.0.0.200?

At 03:47 AM 6/30/2001 -0700, Thomas Salling wrote:
I get quite at lot of these entries from various IP's.

"Jun 30 03:18:38 debbie kernel: Packet log: input DENY eth0 PROTO=17 217.82.6.221:1415 10.0.0.200:137 L=78 S=0x00 I=62563 F=0x0000 T=118 (#5)"

The only access to port 137 is from my local network, so the kernal deny's all access (as it should), but i'm wondering. Is this an attack? If this really is an attach, how come I get "probed" up to 6 times a day? Are there really THAT many scriptkiddies, attackers, hackere or whatever ?

/TL





--
Eric N. Valor
Webmeister/Inetservices
Lutris Technologies
eric.valor@lutris.com

- This Space Intentionally Left Blank -



Reply to: