Hey All! I run a postfix server with spam assassin with pyzor and razor. I just installed ntop, and I have it running with the -q function to see funky packets. Everytime I receive an email I see:
Nov 4 18:40:24 homebox ntop[31182]: **WARNING** Host [slave-tothe-box.net:41354] performed FIN scan of host [shock.cloudmark.com:2703] The port of 2703 is always the same.I know this is one of the checks that the email system makes, but why does ntop see this as a FIN scan? Thanks for the assist! James _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
