all port scan attack!?

  • From: "Farshad Farooji" <farshad@xxxxxxxxxxxxxx>
  • To: isalist@xxxxxxxxxxxxx
  • Date: Sat, 26 Oct 2002 13:57:53 -0600

Hi everyone;

I have been receiving alerts from ISA server almost 50 times a day since I
enabled packet filtering and notifications. just wanted to see if these
are real attacks and what should be done about them. by the way my ISA
server has been getting dynamic IP from the ISP and I haven't had any
problems so far. but I suspect it might have something to do with this
dynamic IP !!?? here is a sample of the logs,

2002-10-26      00:00:07        207.25.71.252   24.78.164.31    Tcp     80      
5959    BLOCKED 24.78.164.31

2002-10-26      00:00:26        200.177.83.3    24.78.164.31    Udp     1046    
137     BLOCKED 24.78.164.31

2002-10-26      00:00:32        207.25.71.252   24.78.164.31    Tcp     80      
5959    BLOCKED 24.78.164.31

2002-10-26      00:01:20        207.25.71.252   24.78.164.31    Tcp     80      
5959    BLOCKED 24.78.164.31

2002-10-26      00:01:42        24.78.165.44    24.78.167.255   Udp     137     
137     BLOCKED 24.78.164.31

2002-10-26      00:01:43        24.78.165.44    24.78.167.255   Udp     137     
137     BLOCKED 24.78.164.31

2002-10-26      00:01:45        24.78.165.44    24.78.167.255   Udp     137     
137     BLOCKED 24.78.164.31

2002-10-26      00:01:46        24.78.165.44    24.78.167.255   Udp     137     
137     BLOCKED 24.78.164.31

2002-10-26      00:02:58        207.25.71.252   24.78.164.31    Tcp     80      
5959    BLOCKED 24.78.164.31

2002-10-26      00:04:58        207.25.71.252   24.78.164.31    Tcp     80      
5959    BLOCKED 24.78.164.31

2002-10-26      00:05:04        207.25.71.252   24.78.164.31    Tcp     80      
6227    BLOCKED 24.78.164.31

2002-10-26      00:05:05        207.25.71.252   24.78.164.31    Tcp     80      
6227    BLOCKED 24.78.164.31


thanks for the help,
Farshad 


Other related posts: