Snort mailing list archives

port 29990 and 51417 scans


From: Dallas Jordan <DJordan () sawgrassink com>
Date: Wed, 30 Oct 2002 11:17:39 -0500

Checking my snort logs this morning, I found several nmap TCP scans to port
29990 from about 6 different IP addresses.  I also noticed that last week we
were scanned from these same addresses on port 51417.  Has anyone else seen
this type of activity?  I tried to find out some info on these ports but
turned up nothing.  I suppose these could be just compromised machines doing
random scans for these ports?  Does anyone know what could be using these
ports?  Thanks. 


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: