Real World Analysis
What’s wrong with the break-in theory? Well, no connections were established, no data exchanged, and
no connections were stopped after being established.
This looks like a typical scan from whatsup.net. Occasionally, you’ll see dns.myplace.com respond
with a RESET/ACK meaning that the port that is being scanned is inactive. Other than that, there is no
evidence of any two-way conversation.
If no RESET/ACK is seen that means that the traffic never actually made it to the inactive port to be
rejected. In other words it was blocked by an exterior router. The sensor for this site resides outside the
filtering router....