Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Serious security issues?

  1. #1
    Keikan's Avatar ........
    Join Date
    Apr 2003
    Location
    Edmonton (Not Enfield)
    Age
    35
    Posts
    3,743
    I turned on my computer today and I noticed that the security log of Sygate Personal Firewall was active (Yes, I probably need a new firewall). I looked at it and I saw that there was a port scan on my computer. No big deal right? But I kept getting port scanned once every minute by the same IP address over and over again. It's also trying to scan every port. Eg. 757,758,759 and then 2 hours later 2609,2610,2611 etc. with it still going on. I do have another computer on a network connected with a hub not a router. When I checked that computer it was getting the same thing from the same IP address. The computers both have Windows XP.

    Should I be worried about this activity? It appears really malicious. Can I call my ISP to change my IP addresses or something?
    Ohh noo!!! I make dribbles!!!

  2. Software & Hardware   -   #2
    Quote Originally Posted by Keikan View Post
    It's also trying to scan every port. Eg. 757,758,759 and then 2 hours later 2609,2610,2611 etc. with it still going on.
    Firewalls sometimes mistake P2P connection attempts as port scanning, but this sounds like a real one, although a bit slow - newer tools can scan 500 ports in a few seconds.

    I'd say you change your IP if possible, call your ISP if that's the only way. Or if you're not able to, block the attacker with a tool like PeerGuardian/PeerBlock or P2PFire.
    Last edited by anon; 12-12-2009 at 11:39 PM.
    "I just remembered something that happened a long time ago."

  3. Software & Hardware   -   #3
    Keikan's Avatar ........
    Join Date
    Apr 2003
    Location
    Edmonton (Not Enfield)
    Age
    35
    Posts
    3,743
    I don't have any P2P programs running right now.
    And yea its around 4 ports/30sec according to the SPF security log...

    Any other way to change IP without calling my isp?
    Ohh noo!!! I make dribbles!!!

  4. Software & Hardware   -   #4
    Quote Originally Posted by Keikan View Post
    Any other way to change IP without calling my isp?
    You could try changing your network card's MAC with a program like "Mac Address Changer" or macshift. Just flip the last byte - for example, if your current MAC is:
    01 02 03 AB CD EF
    Change it to
    01 02 03 AB CD FE
    Then power-cycle your modem. With some luck you'll have a new IP.
    "I just remembered something that happened a long time ago."

  5. Software & Hardware   -   #5
    Quote Originally Posted by Keikan View Post
    Should I be worried about this activity? It appears really malicious. Can I call my ISP to change my IP addresses or something?
    usually ISPs assign temporary WAN IP addresses to residential customers from the ISP's pool of addresses. prolly both as a matter of practicality and to reduce the risk of customers being victimized by network attacks. so... unless you've specifically paid for a permanent WAN IP, rebooting your modem or router should give you a new WAN IP address and put a stop to someone who's been randomly pinging or scanning you. if you're certain that you have a permanent WAN IP, then... yeah, you might need to call your ISP and request a new WAN IP, and explain to them that you suspect a port scanning attack so perhaps they can examine the problem and give you advice if necessary.

    if the scans persist after acquisition of a new WAN IP, it might be wise for you to thoroughly inspect the computers in your home for malware infections. possibly your computers might be broadcasting your IP to an outsider without you being aware of it?

    ALSO: if you really want to put your mind at ease about the possibility of unsolicited connections being attempted by outsiders, you might want to consider using a router that has a NAT feature (network address translation), even if you're only going to use one computer at a time. it might negatively affect your P2P abilities, but it can certainly stop things like port scans from reaching your computer.
    Last edited by 3RA1N1AC; 12-13-2009 at 11:21 AM.

  6. Software & Hardware   -   #6
    karachidude's Avatar Excelsior BT Rep: +5
    Join Date
    Nov 2009
    Location
    Karachi
    Posts
    883
    Commodo is a gud firewal option

  7. Software & Hardware   -   #7
    What? I thought Commodo sucked! I used it because Zone Alarm wouldn't work with the Win7 beta, and I hated its GUI. ZA allows me to control what gets in and what gets out with simple warning popups when I install it with the Manual option. With the Manual option set, nothing is allowed to connect to the net without my permission except ZA itself. Then from that point on I just put a check mark in always allow for system files (isass.exe), anti-virus, spyware apps and browsers and never allow for games and cracked programs.
    The one thing I leave unchecked and therefore continue to get popups for is "Windows Explorer is trying to connect to the net". The reason I leave it unchecked is many programs use it to try and trick you to allow the connection by hiding the fact its them and not Explorer trying to connect. Some programs that do this I want to connect (for activation or updates) and others I do not, so making a check mark choice in this case can cause issues down the road depending on which choice I make. Some things I want to connect will not be able or things I do not want to connect will. Having the option to choose each time Windows Explorer tries to connect is very handy in this circumstance.
    Last edited by Appzalien; 12-13-2009 at 03:35 PM.

  8. Software & Hardware   -   #8
    Quote Originally Posted by 3RA1N1AC View Post
    it might negatively affect your P2P abilities
    Not if you forward your ports
    "I just remembered something that happened a long time ago."

  9. Software & Hardware   -   #9
    Quote Originally Posted by anon-sbi View Post
    Quote Originally Posted by 3RA1N1AC View Post
    it might negatively affect your P2P abilities
    Not if you forward your ports
    of course.

  10. Software & Hardware   -   #10
    Keikan's Avatar ........
    Join Date
    Apr 2003
    Location
    Edmonton (Not Enfield)
    Age
    35
    Posts
    3,743
    Ok. So I've changed my MAC address and power cycled the cable modem and I got a new ip address, still getting the port scans. It's been 24 hours and it's now at 215xx.

    I called my ISP (Shaw) and their response was basically "Meh."
    Perhaps I have malware? I swapped to a Ubuntu live cd and used Firestarter and it reported the same activity from the same IP too.

    I got no more ideas.
    Ohh noo!!! I make dribbles!!!

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •