I am getting what seems to be attacks on a semi regular basis. The information displayed seems to suggest that I am doing the attacks. Since I am not I hope there is something that I am not understanding.
Here is a snippet of a recent email, I have replaced my server address with 'myserver'.
[1:2441:0] A WEB-MISC NetObserve authentication bypass attempt [Classification: Web Application Attack] [Priority: 1]: {PROTO006} myserver:3150 -> 217.150.126.210:80
[1:2441:0] A WEB-MISC NetObserve authentication bypass attempt [Classification: Web Application Attack] [Priority: 1]: {PROTO006} myserver:3155 -> 217.150.126.210:80
[1:2441:0] A WEB-MISC NetObserve authentication bypass attempt [Classification: Web Application Attack] [Priority: 1]: {PROTO006} myserver:3156 -> 217.150.126.210:80
[1:2441:0] A WEB-MISC NetObserve authentication bypass attempt [Classification: Web Application Attack] [Priority: 1]: {PROTO006} myserver:3157 -> 217.150.126.210:80
I am getting attacks indicating CRIT-850/851/860 regularly. Also mysystem is complaining that i am port scanning it from itself with a warning message indicating
A portscan was detected.
The originating source IP address was: myserver
The portscan event was:
spp_portscan: PORTSCAN DETECTED on (null) from myserver (THRESHOLD 10 connections exceeded in 2 seconds)
My server address is the the address that accesses my router.
Do some of the messages mean that the attacks are being reported from that connection?
Help.
This thread was automatically locked due to age.