Checking my snort logs this morning, I found several nmap TCP scans to port 29990 from about 6 different IP addresses. I also noticed that last week we were scanned from these same addresses on port 51417. Has anyone else seen this type of activity? I tried to find out some info on these ports but turned up nothing. I suppose these could be just compromised machines doing random scans for these ports? Does anyone know what could be using these ports? Thanks.
- RE: ports 29990 and 51417 scans Dallas Jordan
- RE: ports 29990 and 51417 scans Jake Scobie
