From owner-freebsd-questions@FreeBSD.ORG Thu Feb 12 08:06:13 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 46FC516A4CE for ; Thu, 12 Feb 2004 08:06:13 -0800 (PST) Received: from p1028-ipbffx02marunouchi.tokyo.ocn.ne.jp (p1028-ipbffx02marunouchi.tokyo.ocn.ne.jp [220.111.132.28]) by mx1.FreeBSD.org (Postfix) with ESMTP id A165643D1F for ; Thu, 12 Feb 2004 08:06:12 -0800 (PST) (envelope-from lukek@meibin.net) Received: (qmail 59482 invoked by uid 89); 12 Feb 2004 16:06:11 -0000 Received: from unknown (HELO ?127.0.0.1?) (192.168.10.35) by 192.168.20.5 with SMTP; 12 Feb 2004 16:06:11 -0000 Date: Fri, 13 Feb 2004 01:01:44 +0900 From: Luke Kearney To: Dragoncrest In-Reply-To: <5.2.0.9.2.20040212110826.00a9b620@pop.voyager.net> References: <5.2.0.9.2.20040212110826.00a9b620@pop.voyager.net> Message-Id: <20040213005928.45CE.LUKEK@meibin.net> MIME-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit X-Mailer: Becky! ver. 2.07.01 cc: freebsd-questions@FreeBSD.ORG Subject: Re: Problem with someone port scanning me X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 12 Feb 2004 16:06:13 -0000 On Thu, 12 Feb 2004 11:12:53 -0500 Dragoncrest granted us these pearls of wisdom: > For the past couple of days I've had someone on our lan port scanning my > box. Not sure what's up with that, but I'm curious if there's a way to log > what IP address this is coming from. I don't have IPFW enabled yet as I > haven't had the time to configure it at this point as it's currently behind > the company firewall on our T3. Is there a way to log where it's coming > from? Or is that already being logged somewhere? I wonder if you might get some benefit from a couple of simple IPF rules and a quick portsentry install. /etc/ipf.rules pass in log on interface0 from any to any pass out log on interface0 from IP to any with the appropriate startup would give you a good idea of the IP address the scan is comming from. Whether your DHCP server admin will tell you who that address is is a different matter. HTH LK