hello all

firstly ill start by telling you everything as ive posted other posts and ao members needed more info from me to help me so if your wondering whys he telling all this unneccessary stuff....thats why..

my problem is
i have a p4 running winxp
zonealarm for a firewall

i keep getting so called port scan alerts from my firewall from varous ip address's and trying various ports.....so i thought ill find out who is port scanning me and report them to there isp's...but when i do a "who is" i get some from outamolgolia and some from my own isp....my point being how do i know a malicious spotty teenager from the so called legitimate internet traffic.....any help would be gratefully accepted


cheers

waterboy

sorry i forgot to add


Final results obtained from whois.ripe.net.
Results:
% This is the RIPE Whois server.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/ripencc/pub-serv...copyright.html

inetnum: 213.45.124.0 - 213.45.125.255
netname: TIN
descr: Telecom Italia S.p.A.
descr: [email protected] service in OSPF Area 12
descr: Wholesale service for ISP
country: IT
admin-c: BS104-RIPE
tech-c: BS104-RIPE
status: ASSIGNED PA
remarks: Please send abuse notification to [email protected]
notify: [email protected]
mnt-by: TIWS-MNT
changed: [email protected] 20001120
changed: [email protected] 20011019
source: RIPE

route: 213.45.0.0/16
descr: INTERBUSINESS
origin: AS3269
mnt-by: INTERB-MNT
changed: [email protected] 20000118
source: RIPE

person: BBBEASYIP STAFF
address: Via Val Cannuta, 250
address: I-00100 Roma
address: Italy
phone: +39 06 36881
e-mail: [email protected]
nic-hdl: BS104-RIPE
notify: [email protected]
changed: [email protected] 20001019
source: RIPE


thats the bumf i get from the who is i am assuning its come from italy??
can anyone help me in understanding the above

thanks again waterboy