12345 is the default netbus port. Someone is probably using the netbus
console to scan for comprimised NT machines on your network.
Carric Dooley
COM2:Interactive Media
http://www.com2usa.com
On Thu, 8 Apr 1999, Evan Brastow wrote:
> Looking at my firewall logs from last night, I noticed something I hadn't
> seen before. An address (ri-1tnt105.efortress.com) essentially tried to get
> through to my entire IP range (sequentially) - every computer on it. The
> service was listed as 12345 and the port as 11111. Protocol was TCP. My
> firewall dropped all of these packets, but nonetheless, that's scary. Was
> this some kind of probe?
>
> Thanks muchly,
>
> Evan
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
>
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]