[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] Portscan message
- Subject: [cobalt-users] Portscan message
- From: Bob G7 <Bob_G7@xxxxxxxxxx>
- Date: Tue Aug 13 20:49:01 2002
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
I got the following message this morning from my RaQ4, all patches/updates:
-A possible port scan of your computer has been detected. Your computer has
-rejected multiple connection attempts from the same source. The following
-line describes the IP packet that rejected the latest attempt:
-eth0:portscan: tcp xx.xx.xx.xx/27374 -> 172.132.45.13/1145 40 rst (16)
Ping Plotter says the offender is AC89D0D.ipt.aol.com
My question is, now that portscanner has done it's job very well, does
portscanner now place the offender into a file to block them from possible
future 'attacks' or do I need to add them to something like 'hosts.deny'. I
check the archives some and Google but I may have missed the answer.
Thanks in advance.