Portscan detected: IN=eth1 OUT=eth0 SRC=68.39.224.5 DST=*.*.*.* LEN=190 TOS=0x00 PREC=0x00 TTL=250 ID=40686 DF PROTO=UDP SPT=53 DPT=38469 LEN=170
It looks like a dns query from a windows machine. I'm not to sure if outlook was open but i'll have to check. I wonder why it's triping as a portscan. thanks mark -----Original Message----- From: Matej Pfajfar [mailto:[EMAIL PROTECTED]]On Behalf Of Matej Pfajfar Sent: Tuesday, March 05, 2002 12:44 PM To: Mark Matrafajlo Subject: Re: comcast port scans Hi Mark. > i keep getting a port scan from 68.39.224.5 (ns01.plnfld01.nj.comcast.net) > obviously a nameserver. Why would they be scanning me ? any help is greatly > appreciated. What port(s) are they scanning? How often and how rapidly? Port 53 by any chance? Mat Matej Pfajfar St John's College, University of Cambridge, UK GPG Public Key @ http://matejpfajfar.co.uk/keys Most people are good people, the rest of us are going to run the world. -- badbytes