xjussix
05-19-2003, 04:01 AM
Here's an example from my portscan2.log:
05/19-07:34:50.722373 TCP src: 80.223.xxx.xxx dst: 66.118.xxx.xxx sport: 1137 dport: 80 tgts: 6 ports: 6 flags: ******S* event_id: 0
05/19-07:34:51.296949 TCP src: 80.223.xxx.xxx dst: 62.94.xxx.xxx sport: 1139 dport: 80 tgts: 7 ports: 7 flags: ******S* event_id: 6
05/19-07:37:58.365919 TCP src: 80.223.xxx.xxx dst: 169.207.xxx.xxx sport: 1107 dport: 80 tgts: 8 ports: 8 flags: ***A***F event_id: 6
There are lots of these in that log. The thing that makes me wonder is what is my computer doing? 80.223.xxx.xxx is MY router's IP (snort is installed in that box). Something weird happening or just something completely normal?
I've "censored" the IP's just in case. =)
05/19-07:34:50.722373 TCP src: 80.223.xxx.xxx dst: 66.118.xxx.xxx sport: 1137 dport: 80 tgts: 6 ports: 6 flags: ******S* event_id: 0
05/19-07:34:51.296949 TCP src: 80.223.xxx.xxx dst: 62.94.xxx.xxx sport: 1139 dport: 80 tgts: 7 ports: 7 flags: ******S* event_id: 6
05/19-07:37:58.365919 TCP src: 80.223.xxx.xxx dst: 169.207.xxx.xxx sport: 1107 dport: 80 tgts: 8 ports: 8 flags: ***A***F event_id: 6
There are lots of these in that log. The thing that makes me wonder is what is my computer doing? 80.223.xxx.xxx is MY router's IP (snort is installed in that box). Something weird happening or just something completely normal?
I've "censored" the IP's just in case. =)