FW: Unsolicited connection to my PC attempted from cc13165-a.zwoll1.ov.nl.home.com
| From: | James Cox | Date: | Mon, 28 Jan 2002 02:34:49 +0000 |
| Subject: | FW: Unsolicited connection to my PC attempted from cc13165-a.zwoll1.ov.nl.home.com | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-8322@lists.php.net to get a copy of this message | ||
oops, forgot to forward
-----Original Message-----
From: James Cox [mailto:imajes@php.net]
Sent: Monday, January 28, 2002 2:34 AM
To: Luis Miguel Viterbo
Subject: RE: Unsolicited connection to my PC attempted from
cc13165-a.zwoll1.ov.nl.home.com
Hello,
I can assure you that this has nothing to do with php.net, but rather a user
on home.com's network who happens to use / or has php installed.
I recommend you email abuse@home.com to rectify this situation.
Sincerely,
James Cox
--
James Cox :: imajes@php.net
Please CC me when replying to my messages on lists.
Was I helpful? http://www.amazon.co.uk/exec/obidos/wishlist/23IVGHQ61RJGO/
-----Original Message-----
From: Luis Miguel Viterbo [mailto:lmviterbo@net.sapo.pt]
Sent: Monday, January 28, 2002 1:19 AM
To: webmaster@php.net
Subject: Unsolicited connection to my PC attempted from
cc13165-a.zwoll1.ov.nl.home.com
Dear Sirs,
My McAfee's Personal Firewall alerted me to the following:
TCP Connection Attempted on Protected Port
SUN Remote Procedure Call (1389/111)
A computer at 212.204.173.69 (cc13165-a.zwoll1.ov.nl.home.com) has attempted
an unsolicited connection to TCP port 111 on your computer.
TCP port 111 is commonly used by the "SUN Remote Procedure Call" service or
program. Remote Procedure Calls (RPC) are used in distributed computer
applications, such as DCOM and Distributed Java. This is a very common port
to be scanned, as it can be used to gain unauthorized access to some
computers running Linux or Unix.
This event may be linked to attempted Hacker activity. Reporting this event
is recommended. Use the 'Report This Event' link in the firewall Log to
report the event.
I understand that the site where the attack was tried from
(cc13165-a.zwoll1.ov.nl.home.com) is related to PHP 4.0 Credits (Zend
Technologies).
I assume you are of good faith, of course, otherwise I wouldn't be sending
you the present email. Could you please find and explain me who can be
trying to access my computer?
Thank you for your concern,
Luis Miguel Viterbo