We just got our server this week, and hired someone to secure it. They finished up this afternoon. A few minutes later, I received this email:

QUOTE
This alert is to notify the addressed users of new server sockets. New server sockets can indicate server-software that has been started on your host, or otherwise be an indication to malicious activity. It is advised to review this alert and investigate if needed.

Following is a summary of new Internet Server Sockets:
> tcp 0 0 67.xx.xx.xxx:22 0.0.0.0:* LISTEN 23361/sshd


Could this be related to some of the security scripts they installed? How do I check this?

Thanks icon_smile.gif