Snort mailing list archives

portscan destination port 137


From: Michael <snorter () gmx net>
Date: Thu, 14 Nov 2002 13:55:11 +0100 (MET)

Hello !!!

I'm using Snort 1.9.0 and I am getting much alerts (portscans) like this:

11/07-05:38:45.031223  UDP src: 210.139.70.184 dst: xxx.yyy.zzz.223 sport:
1026 dport: 137 tgts: 8 ports: 8 event_id: 682

Sometimes there are more than hundred portscans a day. Every time the
destination port is 137.
Is this a real portscan or something else?
Is it possible to ignore portscans to a specific port?

Thanx for you help,
Michael

-- 
+++ GMX - Mail, Messaging & more  http://www.gmx.net +++
NEU: Mit GMX ins Internet. Rund um die Uhr für 1 ct/ Min. surfen!



-------------------------------------------------------
This sf.net email is sponsored by: To learn the basics of securing 
your web site with SSL, click here to get a FREE TRIAL of a Thawte 
Server Certificate: http://www.gothawte.com/rd524.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: