RE: ISA Server port scan attack - servers own external ipaddress
"James C Slora Jr" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Mueller, Eric wrote Tuesday, January 11, 2005 13:06 > ISA Server detected a well-known port scan attack from > Internet Protocol > (IP) address 192.168.1.252. A well-known port is any port in > the range of 1-2048. For more information about this event, > see ISA Server Help. > > This ip address in these message alerts is binded to the > external NIC of the ISA Server. Has anyone experienced this > or has heard of this? You can get these alerts from routine outbound traffic that hits a site multiple times very quickly (such as when loading a web page). Check your outbound proxy and firewall logs around the time of the alert. The logs will show whether you have a portscanning or infection problem, or just an alert threshold problem. Default threshold for portscanning is pretty aggressive. You will have to trade off between getting more occasional false alarms, and missing more actual portscans (if you truly care about them). _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions