/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
This is not necessarily a port scan; more likely the source host is a Win system that
hasn't been secured seeking other Win system names. Then again...
On Mon, 24 Jan 2000, Jake Colman wrote:
>
> I am having a similar problem to that which is being discussed. I am
> regularly finding message log entries such as the following:
>
> ============================================================
>
> Jan 22 19:50:50 firewall kernel: Packet log: input REJECT ppp0 PROTO=17
> 207.198.223.171:137 207.198.222.238:137 L=78 S=0x00 I=51504 F=0x0000 T=125
> (#26)
>
> ============================================================
>
> If I understand correctly, this line indicates that I rejected an incoming
> packet for the netbios name service. Does this mean that someone outside of
> my own network is doing a netbios scan?
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.