Possible port scanning from xxx.xxx.xxx.xxx (spoof?),
I've counted 22 connections.
First connection was made to 135 port at Mon Oct 2 10:58:29 2000
Last connection was made to 135 port at Mon Oct 2 12:10:39 2000
Probably it was SYN scan (0 FIN flags and 22 SYN flags)
사무실 네트워크가 구성
Linux : 메인서버 알짜 6.1(kernel 2.2.14-5.0)
NT4.0 : 프린터와 사내 메일 서버
WIN98 : 클라이언트
xxx.xxx.xxx.xxx는 NT 서버의 IP 입니다.
이러한 구성에서 리눅스 서버 root 계정에 위 내용의 메일을 계속해서 받고 있습니다.
이상이 있어서 그런것인가요?
답변 바랍니다.