I would also download chkrootkit from www.chkrootkit.org to make sure that there is no rootkits (backdoors/trojan horses) installed on the server. david
I just got this this morning, from someone else:
The below information is data from my firewall. As you can see it originated from your site. Can you check nto this and make sure that it does not happen anymore? Thanks for your assistance.
Event Alarms: 1. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1572, protocol TCP (i/f untrust) 2. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1573, protocol TCP (i/f untrust) 3. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1574, protocol TCP (i/f untrust) 4. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1575, protocol TCP (i/f untrust) 5. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1568, protocol TCP (i/f untrust) 6. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1569, protocol TCP (i/f untrust) 7. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1570, protocol TCP (i/f untrust) 8. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1571, protocol TCP (i/f untrust) 9. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1580, protocol TCP (i/f untrust) 10. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1581, protocol TCP (i/f untrust) 11. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1582, protocol TCP (i/f untrust) 12. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1583, protocol TCP (i/f untrust) 13. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1576, protocol TCP (i/f untrust) 14. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1577, protocol TCP (i/f untrust) 15. 2003-07-02 20:23:45 system-alert-00016: Port scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1578, protocol TCP (i/f untrust) 16. 2003-07-02 20:23:45 system-alert-00016: Port Scan has been detected! , From 192.5.41.93/80 to 24.225.5.178/1579, protocol TCP (i/f untrust) occurred 1 times
I ran chkrootkit, and found nothing. Could this possibly be because someone is spoofing me? I have changed my IP number, and the entry in DNS. We'll see if that helps.
Bill Tangren
-- redhat-list mailing list unsubscribe mailto:[EMAIL PROTECTED] https://www.redhat.com/mailman/listinfo/redhat-list