<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2800.1126" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial size=2>I guess that maybe I should have finished the
question. What I would like to know is if anyone has seen this and do you
have any idea if this may be a virus trying to spread or an attack of some
sort. Thanks a bunch.</FONT></DIV>
<BLOCKQUOTE dir=ltr
style="PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV style="FONT: 10pt arial">----- Original Message ----- </DIV>
<DIV
style="BACKGROUND: #e4e4e4; FONT: 10pt arial; font-color: black"><B>From:</B>
<A title=df_collier@hotmail.com href="mailto:df_collier@hotmail.com">Don
Collier</A> </DIV>
<DIV style="FONT: 10pt arial"><B>To:</B> <A title=clue-talk@clue.denver.co.us
href="mailto:clue-talk@clue.denver.co.us">clue-talk@clue.denver.co.us</A>
</DIV>
<DIV style="FONT: 10pt arial"><B>Sent:</B> Wednesday, January 29, 2003 8:56
AM</DIV>
<DIV style="FONT: 10pt arial"><B>Subject:</B> [CLUE-Talk] Quick firewall
question</DIV>
<DIV><BR></DIV>
<DIV><FONT face=Arial size=2>Hello all. I have a real quick firewall
question. I have seen several hits on my firewall on about 5 separate
ports. The repetition of this looks almost virus like on their
part. </FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>The attempts try to get access to ports 3128 6588
80 8080 and 1080. The attempts also come from several different
addresses.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>My computer is connected directly to the WAN with
no LAN link at all. Only one nic. Running RH 7.3 (fully patched)
with iptables fw.</FONT></DIV></BLOCKQUOTE></BODY></HTML>