Hello list,

just installed snort out of curiosity on my network with the plain debian 
default rules. In the reports generated I found one of my sendmail servers 
doing portsweeps to remote adresses adresses.

Upon further investigation I found out that the destination of each occured 
portsweep is also logged by the same sendmail as

...rejecting commands from [a.b.c.d] [a.b.c.d] due to pre-greeting traffic

Now I wonder what this should tell me, these are propably some people's 
spambots which unpolitly don't wait for the server to greet them, sure... but 
why and what does snort detect as a portsweep (what's a portsweep anyway, some 
kind of portscan method?).

I'm pretty confident the server is safe and not compromised, anyone with a clue?


Erik

Reply via email to