Networking Forums

Networking Forums > Computer Networking > Linux Networking > Ghosting IDS Log entries in IPCOP.

Reply
Thread Tools Display Modes

Ghosting IDS Log entries in IPCOP.

 
 
news@celticbear.com
Guest
Posts: n/a

 
      05-16-2005, 07:42 PM
Don't understand this one.
I installed IPCOP on our LAN last Thursday. To test it out I ran an
NMAP portscan on it to see what it would do/say.
Can't say as it DID anything, but it did record the ping of one of the
ports in the IDS Log.

Yet, strangely, it's recording an NMAP attempt every 20 minutes SINCE
then!
Entries like:

Date: 05/16 14:22:35 Name: ICMP PING NMAP
Priority: 2 Type: Attempted Information Leak
IP info: 192.168.1.4:n/a -> 192.168.1.101:n/a
References: none found SID: 469

I looked in /var/log/snort/alert on IPCOP, and the messages are in
there.
I did a
# ps aux | grep nmap
on the original PC (192.168.1.4) and there's no entry.

Why does IPCOP think it's STILL being portscanned by that machine?
What can I do to investigate it further?

Thanks for any help.
Liam

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ghosting Software (Capture/Deploy) RC Windows Networking 0 04-30-2007 07:39 PM
help with ipcop and vpn roy Linux Networking 1 01-19-2006 10:46 PM
Ipcop VPN Freddy Linux Networking 0 01-04-2005 11:37 AM
ipcop and loopback Sauro Linux Networking 5 10-10-2003 10:12 PM
Ipcop Sauro Linux Networking 1 10-08-2003 03:07 PM



1 2 3 4 5 6 7 8 9 10 11