Hey All!

I run a postfix server with spam assassin with pyzor and razor.  I just
installed ntop, and I have it running with the -q function to see funky
packets.  Everytime I receive an email I see:

Nov  4 18:40:24 homebox ntop[31182]:   **WARNING** Host
[slave-tothe-box.net:41354] performed FIN scan of host
[shock.cloudmark.com:2703]

The port of 2703 is always the same.I know this is one of the checks
that the email system makes, but why does ntop see this as a FIN scan?
Thanks for the assist!

James
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to