got this in my logcheck today:
Jun 26 13:02:26 (none) portsentry[28030]: attackalert: Connect from host: 218.89.28.60/218.89.28.60 to TCP port: 139
Jun 26 13:02:26 (none) portsentry[28030]: attackalert: Host: 218.89.28.60 is already blocked. Ignoring
Jun 26 13:02:26 (none) portsentry[28030]: attackalert: Connect from host: 218.89.28.60/218.89.28.60 to TCP port: 139
Jun 26 13:02:26 (none) portsentry[28030]: attackalert: Host: 218.89.28.60 is already blocked. Ignoring
I know that the offending ip was already blocked, but did I misread the faq? I thought that tcp:139 was blocked by linode:
http://www.linode.com/products/faq.cfm :
The following ports are filtered for security reasons. If you need to run a specific service, run it on a different port.
[snip]
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
[snip]
or .. is it outgoing packets that are blocked but not input ?