ms-sql-m hits
Just curious on why my Firewall keeps reporting hits on port 1433-34 for TCP and UDP for service Ms-sql-s and -m? The FW does not report it as a "serious" hit but as a normal hit. I dont have Windows 2000 as I read of a old worm that hit that server a couple of years ago. Now im thinking since I connected to Comcast they maybe sending these hits? When I run a trace on ONE of the multiple Source IP's I get:
TraceRoute to 146.101.136.140 [IVIEWNMS]
Hop (ms) (ms) (ms) IP Address Host name
1 0 0 0 66.98.244.1 gphou-66-98-244-1.ev1.net
2 0 10 0 66.98.241.4 gphou-66-98-241-4.ev1.net
3 0 0 0 66.98.240.7 gphou-66-98-240-7.ev1.net
4 1 1 1 216.200.251.161 ge-6-0-1.mpr2.iah1.us.above.net
5 14 14 14 64.125.29.65 so-5-0-0.mpr1.atl6.us.above.net
6 14 14 14 64.125.27.50 so-0-0-0.mpr2.atl6.us.above.net
7 25 25 25 64.125.29.38 so-3-1-0.cr1.dca2.us.above.net
8 97 96 97 64.125.31.185 so-6-0-0.cr1.lhr3.uk.above.net
9 97 96 96 208.184.231.150 pos0-0.er1a.lhr3.uk.above.net
10 294 315 355 213.152.232.19 213-152-232-19.available.lhr.above.net
11 108 109 108 154.32.3.105 -
12 108 108 108 154.32.101.2 lhc-mfr-1.cr-mfr-1.dmz.uk.psi.net
13 109 108 108 146.101.0.6 core2.lond1-ge1.dc.uk.psi.net
14 131 108 108 146.101.0.62 colo1.lond1-ge1-2.dc.uk.psi.net
15 108 108 108 146.101.136.140 IVIEWNMS
Other IPs report IP address: 220.166.172.68
No host name is associated with this IP address or no reverse lookup is configured.
Running Netstat-nar looks fine....should I be concerned?
Running FC4
thxs
dareino
|