안녕하세요?
오늘 질문을 많이 올리는군요 ^^;;
아래와 같은 메일이 자주 옵니다
메일을 보내는 사람은 SCANDETD at www.xxxxxxx.co.kr 저희 서버 scandetd 가 보내오는것 같은데...
이건 저희 리눅스 서버가 해킹 당하는것이 아닌지 궁굼해서...
아시는분 제발 답변 주세요 ...
Possible port scanning from xxx.xxx.xxx.xxx (spoof?),
I've counted 21 connections.
First connection was made to 445 port at Mon Mar 19 15:57:21 2001
Last connection was made to 445 port at Mon Mar 19 16:07:03 2001
Probably it was SYN scan (0 FIN flags and 21 SYN flags)