snort output
Posted: Thu Jan 05, 2006 8:27 am
I was wondering anybody has seen snort produce this kind of output before.
Events from same host to same destination using same method
=========================================================================
# of from to method
=========================================================================
10 192.168.xxx.xxx 216.39.69.100 (portscan) TCP Portscan
8 192.168.xxx.xxx 216.39.69.100 (portscan) TCP Portsweep
6 192.168.xxx.xxx 194.129.79.6 (portscan) TCP Portsweep
6 192.168.xxx.xxx 194.129.79.6 (portscan) TCP Portscan
2 192.168.xxx.xxx 216.39.69.77 (portscan) TCP Portsweep
2 192.168.xxx.xxx 216.39.69.77 (portscan) TCP Portscan
the 192 address is my local machine so the port scans/sweeps are coming from my computer.
could this possibly something like a zombie or something phoning home. because I did not do any kind of port snooping when this report was created. nmap isn't even on the box.
I guess what worries me is that the 194 address is owned by an isp in amsterdam and the 216 address is owned by savis. and I have nothing to do with those isps.
anyway during this time I went to the stealth port detection site to test my box and I am thinking maybe that has something to do with it but I am not sure and I don't see any of those ip's associated with that site. but I have never seen this before and this box has been up for months.
Events from same host to same destination using same method
=========================================================================
# of from to method
=========================================================================
10 192.168.xxx.xxx 216.39.69.100 (portscan) TCP Portscan
8 192.168.xxx.xxx 216.39.69.100 (portscan) TCP Portsweep
6 192.168.xxx.xxx 194.129.79.6 (portscan) TCP Portsweep
6 192.168.xxx.xxx 194.129.79.6 (portscan) TCP Portscan
2 192.168.xxx.xxx 216.39.69.77 (portscan) TCP Portsweep
2 192.168.xxx.xxx 216.39.69.77 (portscan) TCP Portscan
the 192 address is my local machine so the port scans/sweeps are coming from my computer.
could this possibly something like a zombie or something phoning home. because I did not do any kind of port snooping when this report was created. nmap isn't even on the box.
I guess what worries me is that the 194 address is owned by an isp in amsterdam and the 216 address is owned by savis. and I have nothing to do with those isps.
anyway during this time I went to the stealth port detection site to test my box and I am thinking maybe that has something to do with it but I am not sure and I don't see any of those ip's associated with that site. but I have never seen this before and this box has been up for months.