[Snort-users] RE: smtp scans

Marcus Nelson jtmyfj at ...892...
Thu Nov 30 16:15:41 EST 2000


Ok, figured it out.

Dshield.org and portscan.cablemodem.com are affiliated.  I was testing the
Dshield firewall reporting script on my IDS box.  Due to a perl script
error, I sent a test message without a return address.  The MailServer at
206.34.203.20 handles mail for both sites.  It attempted to respond to my
message based on my IP address, hence the smtp attempts.

Sorry for the confusion.

Thanks,

Marcus

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20001130/2f88b9a3/attachment.html>


More information about the Snort-users mailing list