Hi, 

every day i get something like this in my logs (and right on the terminal as
well). I think it is someone trying to connect, but then shouldn't
portsentry catch it and block it?

Jun 25 08:03:12 musashi kernel: auditIN=eth0 OUT=
MAC=00:90:XX:03:f7:96:00:05:XX:52:58:1c:08:00 SRC=193.204.135.164
DST=(my ip address) LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=59607 DF PROTO=TCP
SPT=4412 DPT=111 WINDOW=32120 RES=0x00 SYN URGP=0

the src ip address is usually different, but there are a few addresses that
appear frequently.

I am not running any internet services at all - xinet is not even installed.
I have the firewall (from the control center) set up, with only a hole for
ssh (which i haven't installed yet).

So, what is this and is it something to worry about? 


-- 
Chris and Yoshiko Spackman

www.openhistory.org
[EMAIL PROTECTED]  (English)
[EMAIL PROTECTED]   (Japanese)

"I will not be pushed, filed, stamped, indexed, briefed, debriefed, or
numbered. My life is my own."
-The Prisoner

PGP signature

Reply via email to