Hello Rob & others on this TB! list & following this thread,

Tuesday, September 18, 2001,  you stated regarding Port 80:

DH>> I use the atGuard firewall and have been getting a high number of
DH>> "inbound TCP network communications" to http port 80,

R> probably CodeRed(II) probes ; i'm still getting them too ...
R> if atGuard logs any packets, see if the string "GET /default.ida?XXX.."
R> is in there ...

I haven't been checking the log (assuming there is one - which is
likely - and that I did set it to record - I could check thatlater),
but atGuard was giving me the IP address in each case. IAC, a lot of
different IP address were used and so they may have been spoofed. I
also considered the possibility that the ISP was checking my use of
the service. For now, Opera is working fine and none of them are
coming in with atGuard stopping any and all attempts, but I could
eliminate the rule and set atGuard to log, if that would accomplish
anything.

Douglas



-- 
________________________________________________________
Archives   : http://tbudl.thebat.dutaint.com
Moderators : mailto:[EMAIL PROTECTED]
TBTech List: mailto:[EMAIL PROTECTED]
Unsubscribe: mailto:[EMAIL PROTECTED]
Latest Vers: 1.53d

Reply via email to