[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Hosts.all/Hosts.deny vs. a firewall?]



On Sun, Aug 27, 2000 at 04:42:13PM +0000, Pollywog wrote:
> Since the most recent IP address change, I have been seeing in my 
> logs attempted connections to ports 137, 138, and 139 but I am
> not concerned because I am guessing that someone was running a 
> server there before I got the IP address.

On a cable modem machine I, too, often see connects to ports 137-139.
Now, are these intentional? They obviously *can* be.

What if a windos user goes into the "network environment" and 
searches and so forth... those broadcasts'll get logged, too, right?
That would explain why those are the ports that most frequently 
get logged.

> I run portsentry and logcheck together and it works well for me.

I can't find portsentry in potato. Is the name mispelled or is it 
woody-only?

Cheers
Sven



Reply to: