I have Comodo firewall, and for the past 6 hours (straight, every 5 or 10 seconds) I have been getting "Inbound Policy Violations" from an IP which resolves to a Telkom ADSL IP (comparing with IP's obtained on international and local accounts, it's an international account).
This entity keeps on trying to get in on port 1194. Always port 1194 on my side that they trying to exploit. The funny thing is, (maybe not so funny, I have no idea what this person is doing) is that on thier side, the port they are using to scan my port 1194 is increasing. So one scan will be from <freak>:50000 to <me>:1194 the next from <freak>:500001 to <me>:1194 where <freak> represents the IP of the scanner and <me> is my (local SAIX) IP.
It seems like some sort of scan, but it doesn't make sense to me that the ports on thier side is increasing; if they were scanning me wouldn't the ports on my side be changing ?!
If anyone knows what this is, please let me know
This entity keeps on trying to get in on port 1194. Always port 1194 on my side that they trying to exploit. The funny thing is, (maybe not so funny, I have no idea what this person is doing) is that on thier side, the port they are using to scan my port 1194 is increasing. So one scan will be from <freak>:50000 to <me>:1194 the next from <freak>:500001 to <me>:1194 where <freak> represents the IP of the scanner and <me> is my (local SAIX) IP.
It seems like some sort of scan, but it doesn't make sense to me that the ports on thier side is increasing; if they were scanning me wouldn't the ports on my side be changing ?!
If anyone knows what this is, please let me know