Snort mailing list archives
portscan destination port 137
From: Michael <snorter () gmx net>
Date: Thu, 14 Nov 2002 13:55:11 +0100 (MET)
Hello !!! I'm using Snort 1.9.0 and I am getting much alerts (portscans) like this: 11/07-05:38:45.031223 UDP src: 210.139.70.184 dst: xxx.yyy.zzz.223 sport: 1026 dport: 137 tgts: 8 ports: 8 event_id: 682 Sometimes there are more than hundred portscans a day. Every time the destination port is 137. Is this a real portscan or something else? Is it possible to ignore portscans to a specific port? Thanx for you help, Michael -- +++ GMX - Mail, Messaging & more http://www.gmx.net +++ NEU: Mit GMX ins Internet. Rund um die Uhr für 1 ct/ Min. surfen! ------------------------------------------------------- This sf.net email is sponsored by: To learn the basics of securing your web site with SSL, click here to get a FREE TRIAL of a Thawte Server Certificate: http://www.gothawte.com/rd524.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- portscan destination port 137 Michael (Nov 14)
- Re: portscan destination port 137 twig les (Nov 14)
- <Possible follow-ups>
- Re: portscan destination port 137 Eric Joe (Nov 14)
- Re: portscan destination port 137 twig les (Nov 14)
- RE: portscan destination port 137 Security Admin (Nov 14)
- Re: portscan destination port 137 Axel Pettinger (Nov 14)
- RE: portscan destination port 137 Security Admin (Nov 14)