[Snort-users] Newbie: What does this mean?

John Plate plate at ...13254...
Tue Apr 12 12:58:32 EDT 2005

Sean Brown wrote:

> I have been getting the same entry in my logs with Hotmail/Microsoft
> servers being the destination and my public IP as the source. Guess
> where points to.
> I've just been ignoring it.

Yes - but it could be some Trojan Horse hidden somewhere on the server
making/testing a coordinated attack. 

We still miss the explanation why the traffic seems to come from my
server, right?

I've tried with netstat -l and looked at all active processes, but I
cannot find anything suspicious. 


More information about the Snort-users mailing list