On 2004.04.12 10:09, bjsamuels@beenthere-donethat.org.uk wrote:
This problem has occurred around the time I've started getting the following in my router logs (this is the first recorded instance):
Thu, 2004-04-08 16:52:17 - TCP Packet -Source:81.174.175.111,3789 Destination:81.174.175.161,3127 - [DOS] Thu, 2004-04-08 16:52:21 - TCP Packet - Source:81.174.175.111,1603 Destination:81.174.175.161,1025 - [DOS]
...
Looks like someone is port scanning hoping to find something to exploit. If you firewall isn't allowing incoming connection you should be safe, even so it is good to complain to your ISP. The ports being scanned and their respective services seem to be:
135 - empmap 139 - netbios-ssn 1025 - blackjack 3127 - mydoom 6129 - dameware
Probing netbios-ssn is no doubt an attempt to see if you have your hard disk shared via windows networking (or samba). Perhaps the other services are also known to have security issues. None of this seems to having anything to do with FTP though.
Steve.