I don't know about the rest of those, but 1080 is a very
common port to get connect attempts on these days.
People probing for open socks proxies to launder their
connections through. 23 is also fairly common to scan
for for instance Wingate on. Even if 1080 is closed
it might still allow a telnet launder on 23.


--
Frode


-----Original Message-----
From: Scott Jangro <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED] <[EMAIL PROTECTED]>
Date: 20. desember 1998 17:51
Subject: [masq] interpreting ipfwadm logs


[snip]
IP fw-in deny eth0 TCP 153.36.25.22:17031 x.x.x.x:1080 
IP fw-in deny eth0 TCP 153.36.25.22:17031 x.x.x.x:1080 

IP fw-in deny eth0 TCP 24.0.165.89:3230 x.x.x.x:23 
IP fw-in deny eth0 TCP 24.0.165.89:3230 x.x.x.x:23 
[snip]

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
For daily digest info, email [EMAIL PROTECTED]

Reply via email to