Hi Leonard,

LdO>  What is this? Some kind of stealth scan? I've seen a couple of these in the
LdO> last few days (same offender, same ports).

LdO> Feb 20 21:21:30 firewall kernel: Packet log: i_e1_udp ACCEPT eth1 PROTO=17
LdO> 213.93.106.142:5881 213.93.11.73:5882 L=29 S=0x00 I=53280 F=0x0000 T=125 (#7) 

It is likely that someone is looking for an ICQ trojan. It makes its home
on those ports.

For more info http://www.simovits.com/trojans/tr_data/y1157.html

Have fun,
-- 
_________________________________________________________________
 Brian Ashe                     CTO
 [EMAIL PROTECTED]              Dee-Web Software Services, LLC.
 http://www.dee-web.com/
-----------------------------------------------------------------
You don't have to swim faster than the shark...
You just have to swim faster than the people you're with.




_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to