Results 1 to 3 of 3
Thread: Logwatch question
-
05-07-2004, 08:39 AM #1Aspiring Evangelist
- Join Date
- Dec 2003
- Posts
- 378
Logwatch question
I just receive my Logwatch, what's mean ??
Warning: Portscans detected
TCP SYN/Normal from:
0-1pool12-113.nas8.milwaukee1.wi.us.da.qwest.net (63.156.12.113): ports: 135
0-1pool201-123.nas6.birmingham1.al.us.da.qwest.net (65.141.201.123): ports: 445
061093097204.ctinets.com (61.93.97.204): ports: 559
0x5358909c.sdbnxx2.adsl-dhcp.tele.dk (83.88.144.156): ports: 135
107.int29.dsl.garlic.net (216.139.29.107): ports: 445
131.228.mariettafiber.net (216.235.131.228): ports: 445
157.25.92.62: ports: 135
160.Red-83-35-41.pooles.rima-tde.net (83.35.41.160): ports: 445
172.27.54.49: ports: 445
181.Red-80-33-48.pooles.rima-tde.net (80.33.48.181): ports: 445
185-203.SPEEDe.golden.net (216.75.185.203): ports: 135 445
187-86.SPEEDe.golden.net (216.75.187.86): ports: 445
192.Red-80-35-48.pooles.rima-tde.net (80.35.48.192): ports: 445
1Cust145.tnt2.regina.sk.da.uu.net (216.95.48.145): ports: 445
1Cust202.tnt36.dfw9.da.uu.net (67.234.81.202): ports: 135
202.57.163.165: ports: 445
-
05-07-2004, 09:13 AM #2Web Hosting Master
- Join Date
- Dec 2001
- Posts
- 5,221
Greetings:
It means some one is scanning your server; and most likely for Microsoft Window vulnerabilities.
See http://nsit.uchicago.edu/alert/port-135.html , http://ntsecurity.nu/papers/port445/ , and http://www.petri.co.il/what_is_port_445_in_w2kxp.htm
Thank you.
-
05-07-2004, 12:46 PM #3Aspiring Evangelist
- Join Date
- Dec 2003
- Posts
- 378
ic.. 10q