[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] constant "scans"



> Heya Folks,
> 
> Port sentry keeps reporting the following scans:
> 
> 	Mar 20 07:41:55 www portsentry[20348]: attackalert: TCP 
> SYN/Normal scan 
> from host: 61.43.142.241/61.43.142.241 to TCP port: 445
> 
> There have been alot of reports over the last week or so. All 
> from varying 
> IP's and all to port 445.
> Is this a default windows update port or something ? Or is 
> this an actual 
> threat ?
> 

Maybe they think it's an MS Server
http://www.infosecuritymag.com/2002/apr/digest25.shtml#news2
-- 
C2003 Dan Kriwitsky

Please reply to the list only. Off list replies are not read.