I am receiving scanlogd messages from ftp.gwdg.de there is a wget ftp download scrip there is running yet this is the first time I am getting messages like this the downloading machine is masquared should the inner ip be as my real ip. Can someone give a guidance what to check for TIA -- Togan Muftuoglu Unusual System Events =-=-=-=-=-=-=-=-=-=-= May 16 15:41:34 gardiyan scanlogd: 134.76.11.100:20 to 192.168.1.3 ports 2549, 2550, 2551, 2552, 2553, 2554, 2555, ..., ??r??uxy, TOS 08, TTL 41 @15:40:50 May 16 15:52:11 gardiyan scanlogd: 134.76.11.100:20 to 192.168.1.3 ports 2715, 2716, 2717, 2718, 2719, 2720, 2721, ..., ??r??uxy, TOS 08, TTL 41 @15:51:26 May 16 15:53:12 gardiyan scanlogd: 134.76.11.100:20 to 192.168.1.3 ports 2744, 2745, 2746, 2747, 2748, 2749, 2750, ..., ??r??uxy, TOS 08, TTL 41 @15:52:28 May 16 15:59:00 gardiyan /USR/SBIN/CRON[10460]: (root) CMD ( rm -f /var/spool/cron/lastrun/cron.hourly) ----- End forwarded message ----- -- Togan Muftuoglu