Hi, At 17:23 20-02-2004, Robert Morse wrote:
I have been seeing a lot of attackalerts on our RAQ2 like this lately: Feb 20 04:42:32 admin portsentry[1312]: attackalert: Connect from host: client302.gdal1.hawkcommunications.com/64.63.216.141 to TCP port: 1080
It's a proxy scan. Don't worry about it unless the host scans a significant number of ports. If it annoys you, you can blackhole that IP address. You can browse the mailing list archives for the usual debate about port scans. :)
Regards, -sm