We just hooked up a Tipping point (attack mitigator) to my work network, which pretty much blocks attacks from internet worms such as netsky, bagel, blaster, mydoom, etc... and will tell us from where and what IP is being attacked. It also strips virii from email traffic also, but thats another story.
A few minutes after it was hooked up, it reported that my Powerbook was running a "Possible NMAP scan (FIN no ACK)" on a DSL ip in california (69.110.22.112)??
I didn't have any programs open except quicksilver (at least showing in the dock). I didnt get a chance to check activity monitor and just rebooted my system.
Anyone heard of any suspicious activity like this before?
Since the reboot nothing has been reported yet, I'm going to try opening programs one by one until I hit something....