Ciao a tutti,
ho ricevuto questa mail
Hello from USinternetworking (USi). I am a Security Engineer here
trying to track down a security incident that appears to have originated
from your network on September 16, 2005. Please investigate a TCP sweep
of port 80 from the IP xxx.xxx.xxx.xxx and inform me of the results
(account cancelled, user warned, etc). I will require this information
in order to close the ticket on this activity. I have attached a
portion of the log details as evidence. All times are EDT.
00:39:17 xxx.xxx.xxx.xxx 0.0.0.0 [TCP-SWEEP]
(total=315,dp=80,min=172.25.0.20,max=209.135.50.18 9,Sep16-00:39:01,Sep16
-00:39:17) (neids1)
00:40:14 xxx.xxx.xxx.xxx 0.0.0.0 [TCP-SWEEP]
(total=423,dp=80,min=209.135.47.217,max=209.135.63 .183,Sep16-00:39:17,Se
p16-00:39:32) (neids1)
qualcuno potrebbe consigliarmi come verificare/risolvere il problema....
dovrei fare uno scan port .... ma:
quale software mi consigliate?
successivamente come posso intervenire? (W2000)
Grazie

Rispondi quotando
. si è firmato questo tizio?
