[Dshield] Scanning from 127.0.0.1

Deb Hale haled at pionet.net
Fri Sep 26 13:21:36 GMT 2003


I have been seeing this kind of activity now off and on for the last 2
weeks.  I have noticed that the majority of the activity has occurred after
6:00pm central time.  No idea what is going on.


-----Original Message-----
From: list-bounces at dshield.org [mailto:list-bounces at dshield.org] On Behalf
Of Bruce & Roma
Sent: Thursday, September 25, 2003 7:00 PM
To: list at dshield.org
Subject: [Dshield] Scanning from 127.0.0.1


Good Evening List;

I have noticed some unusual scanning activity that was blocked by my
personal firewall yesterday and today.

Details as follows:


24/09/03 07:20:29 PM Inbound TCP to local port ="1092"  Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

24/09/03 07:22:14 PM Inbound TCP to local port ="1307"  Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

25/09/03 07:21:57 PM Inbound TCP to local port ="1680" Remote Port="80" 
Remote IP="127.0.0.1" Action Prevented

What I do not understand is how this was ever routed, especially if my ISP
is doing it's job properly.

Since CvtWin filters these types of scans these were not reported in my 
daily  scan submission.

Has anyone else encountered something similar lately?  Although possibly 
just a coincidence,
all instances I've encountered have been during the same time frame (just 
after 7:20PM), yesterday and today.


Thanks.

Bruce

_______________________________________________
list mailing list
list at dshield.org
To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list






More information about the list mailing list