  detth Onemhz On Aim
join:2000-10-06 Astoria, NY
| strange pptp from one of my servers
Hi all,
was logged onto one of my mail servers today, and randomly did a netstat, and i see a weird connection. there is an open and establish PPTP via HTTP to 218-228-220-5.eonet.ne.jp.
I dont remember ever dealing with this address for anything. I always patch boxes asap, run AV software, and software firewalls, and this box sits behind a hw firewall too.
any ideas on what this could be? |
|
  keith2468 Premium,MVM join:2001-02-03 Winnipeg, MB
| Is 218.228.220.5 their IP address? The name often has the IP address incorporated in it, but names can be anything.
It is behind a HW FW. So does that mean the connection had to be initiated from your system? So a trojan maybe?
I would start with a virus scan with updated signatures, since it is easy to do.
Also see if there is any evidence of spam flowing out of your system. |
|
  detth Onemhz On Aim
join:2000-10-06 Astoria, NY | yes it is their ip address. and the connection was initiated by my machine. I run weekly virus scans, and have a trojan guard app running. No spam seems to be flowing out via the normal ways, traffic seems normal. this is wierd.. |
|