Well-known port scan attack

  • From: "Manfred" <md.fk@xxxxxxx>
  • To: isalist@xxxxxxxxxxxxx
  • Date: Mon, 8 Sep 2003 02:56:13 -0600

Hi,

the last weeks I get plenty of port scan alerts from the address
127.0.0.1. I had them never before. In the log files I have entries from
lokalhost like this:
Date  Time  127.0.0.1  x.x.x.x   Tcp  80  1864  BLOCKED  x.x.x.x
(x.x.x.x = public ISA IP)

How can I find out the process which is triggering this traffic and these
alerts?

Thank you,
Manfred


Other related posts: