[Dshield] Scanning from 127.0.0.1

Bruce & Roma ecarew2531 at rogers.com
Thu Sep 25 23:59:35 GMT 2003


Good Evening List;

I have noticed some unusual scanning activity that was blocked by
my personal firewall yesterday and today.

Details as follows:


24/09/03 07:20:29 PM Inbound TCP to local port ="1092"  Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

24/09/03 07:22:14 PM Inbound TCP to local port ="1307"  Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

25/09/03 07:21:57 PM Inbound TCP to local port ="1680" Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

What I do not understand is how this was ever routed, especially if
my ISP is doing it's job properly.

Since CvtWin filters these types of scans these were not reported in my 
daily  scan submission.

Has anyone else encountered something similar lately?  Although possibly 
just a coincidence,
all instances I've encountered have been during the same time frame (just 
after 7:20PM), yesterday and today.


Thanks.

Bruce




More information about the list mailing list