I am getting an alert from my security program that SatGuys 70.85.58.122 is scanning me with the NMap Xmas Scan; what's up?
Do you have a timestamp on this log entry, and is your clock sync'd?charper1 said:NP! Thanks, I feel a bit better now. Thought you might want a copy of my log entry.
Details: Intrusion: NMap Xmas Scan.
Intruder: www.satelliteguys.us(70.85.58.122).
Risk Level: Medium.
Source IP address: www.satelliteguys.us(70.85.58.122).
Destination IP address: OFFICE(192.168.0.20).
TCP Source Port: http(80).
TCP Destination Port: 4280.
TCP Header Flags: 0x00000829. These TCP Flags are invalid.
Thanks. The only thing I see close to that time in our logs:charper1 said:I run a clock sync every morning from the worldtimeserver so it should be right on.
8:36:23pm (EST) was the logged time.
and since your address is NAT'd, I can't be sure if it's related. (I doubt it).Jul 16 20:36:22 host kernel: ** IN_UDP DROP ** IN=eth0 OUT= MAC=00:0f:1f:f8:cf:22:00:11:bb:37:10:ff:08:00 SRC=152.163.159.222 DST=70.85.58.116 LEN=239 TOS=0x00 PREC=0x00 TTL=50 ID=0 DF PROTO=UDP SPT=9052 DPT=32769 LEN=219
absolutely. We need to know if our server is doing stupid thingscharper1 said:Do you want to know if it happens again?
Same here as well, but I'm stuck behind a hotel NAT, so I don't know whatkorsjs said:don't know if this will help, but i use norton firewall and system works and have NOT had anything funny.