SV650.org - SV650 & Gladius 650 Forum



Idle Banter For non SV and non bike related chat (and the odd bit of humour - but if any post isn't suitable it'll get deleted real quick).
There's also a "U" rating so please respect this. Newbies can also say "hello" here too.

Reply
 
Thread Tools
Old 23-04-06, 03:43 PM   #1
Razor
Guest
 
Posts: n/a
Default WTF is a port scan attack?

I've installed this new firewall and it keeps telling me about these port scan attacks.
It seems to block them and I can back trace to see where they come from, or some of them I can anyway.

What should I do make a complaint?

role: Modem and DSL Team
address: Energis UK
address: Melbourne Street
address: Leeds, LS2 7PS
address: United Kingdom
phone: +44 113 2345100
abuse-mailbox: abuse@energis.com
admin-c: ENIT1-RIPE
tech-c: ENIT1-RIPE
nic-hdl: MADM1-RIPE
remarks: Abuse reports to abuse@energis.com please!
remarks: No actions are taken on abuse reports sent to modem team.
mnt-by: ENERGIS-MNT
source: RIPE # Filtered

% Information related to '81.78.0.0/15AS5388'

route: 81.78.0.0/15
descr: Energis UK

This was a few minutes ago while I was on here?
  Reply With Quote
Old 23-04-06, 04:04 PM   #2
TSM
The Sick Man
Mega Poster
 
TSM's Avatar
 
Join Date: Nov 2004
Location: Peckham.SE.LDN
Posts: 4,768
Default

Nop this site is not on energis net work its pipex and its ip starts 195.*.*.* etc.

Some ISPs, like Zen have an active policy to port scan certian things with their clients and if its found that you are at risk they email you.
__________________
OTR: KTM 690 Duke R 2015 Full Akro
SIDELINE: Kwak ZX636 A1P 2002, Red, R&G's, Yoshi, Double Bubble Screen
GONE: Kwak ZX-7R P1, Full Akro, Undertray, Screen
GONE: SV650S K2 Very Bruised & Without Fairing, Motovation Frame Sliders, R&G Ally Sprocket Toe Protector, HEL 2 Line Setup, GSXR K1 600 RWU Forks, Barnett Clutch & Springs, Penske 8981 Shock, Gilles Ti Rearsets, Steel Barends, Scottoiler, AFAM Chain & Sprockets, Twin FIAMM Horns, Skidmarx Bellypan, Full Micron Zeta Steel System, Cut down undertay.

Forum Problems & Information / Site Suggestions
TSM is offline   Reply With Quote
Old 23-04-06, 05:20 PM   #3
tigersaw
Member
Mega Poster
 
tigersaw's Avatar
 
Join Date: Mar 2005
Location: Llanwrtyd Wells Powys
Posts: 1,146
Default

have you been downloading music or torrents??? Often firewalls mistake peer to peer connections as port scan attacks.
tigersaw is offline   Reply With Quote
Old 23-04-06, 05:20 PM   #4
Razor
Guest
 
Posts: n/a
Default

Nope don't use torrents or download music that much.
  Reply With Quote
Old 23-04-06, 07:18 PM   #5
timwilky
Member
Mega Poster
 
timwilky's Avatar
 
Join Date: Mar 2004
Location: Not in Yorkshire. (Thank God)
Posts: 4,116
Default

OK to answer your question "WTF is a port scan attack"

OK I am going to treat you like a muppet, you may not be, in fact because you have a firewall I know you not to be.

TCP/IP uses defined ports for services.
For a list look at your services file but will look a bit like

tcpmux 1/tcp # TCP port service multiplexer
tcpmux 1/udp # TCP port service multiplexer
rje 5/tcp # Remote Job Entry
rje 5/udp # Remote Job Entry
echo 7/tcp
echo 7/udp
discard 9/tcp sink null
discard 9/udp sink null
systat 11/tcp users
systat 11/udp users
daytime 13/tcp
daytime 13/udp
qotd 17/tcp quote
qotd 17/udp quote
msp 18/tcp # message send protocol
msp 18/udp # message send protocol
chargen 19/tcp ttytst source
chargen 19/udp ttytst source
ftp-data 20/tcp
ftp-data 20/udp
# 21 is registered to ftp, but also used by fsp
ftp 21/tcp
ftp 21/udp fsp fspd
ssh 22/tcp # SSH Remote Login Protocol
ssh 22/udp # SSH Remote Login Protocol
telnet 23/tcp
telnet 23/udp
# 24 - private mail system
lmtp 24/tcp # LMTP Mail Delivery
lmtp 24/udp # LMTP Mail Delivery
smtp 25/tcp mail
smtp 25/udp mail ad so on

so a port scan is simply a device out on the internet that is sequencing through the port numbers trying to find a hole through your firewalll

Assumming you might run a couple of services for a home based server, you may for instance allow ssh traffic from the net on port 22 or mail on port 25 or pop3 on port 110 etc.

The box out there is simply looking for these holes. once it finds them then they may start to try to find a hole in the application behind the port such as a buffer overflow etc.

Please note ISPs also run checks on their own networks looking for servers that do not conform to their use policy etc. So if you isp does not want you to host services he could do a port scan on every device on his network.

I run a couple of tools on my servers to look for attacks, including port scans, where I detect them I then automatically drop packets that match the offending ip address, therefore having attempted a port scan against me etc then the offending device is prevented from using ports that I have open such as maill/http.

I am please that you use a firewall and even better look at the logs. You would not believe the number of people out there living in blissfull ignorance asssuming they are safe because they have a firewall. Vigilence is the most important part of any security policy
__________________
Not Grumpy, opinionated.
timwilky is offline   Reply With Quote
Old 24-04-06, 01:09 PM   #6
Terence
Guest
 
Posts: n/a
Default

and what to do if you are being port scanned?

Its a bit like having your front door open so people can see into your house. you can't stop them from walking by, but you can stand at the door to make sure you don't let just anybody in...

You can't stop people from trying to port-scan you, but you can make sure that if they try to connect to you that are stopped by the firewall.
  Reply With Quote
Old 24-04-06, 01:48 PM   #7
Ward8124
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Terence
and what to do if you are being port scanned?

Its a bit like having your front door open so people can see into your house. you can't stop them from walking by, but you can stand at the door to make sure you don't let just anybody in...

You can't stop people from trying to port-scan you, but you can make sure that if they try to connect to you that are stopped by the firewall.
Not a lot mate sit back and rest easy if you are sure that all your ports are closed off, by default all firewalls that ive come across have their ports closed and some also require rules to forward to various places on the LAN/DMZ?WAN so unless you specifically opened a port the attacker will have a tough job trying to get through.

If you are getting persistant attacks from certain ip address you can run a whois search on the net and send email to the ISP that hosts the IP.
  Reply With Quote
Old 24-04-06, 06:07 PM   #8
Razor
Guest
 
Posts: n/a
Default

Thanks folks
  Reply With Quote
Old 24-04-06, 07:32 PM   #9
Spiderman
Where the hell am I?
Mega Poster
 
Spiderman's Avatar
 
Join Date: Dec 2004
Location: Swingin' thru the urban jungle
Posts: 7,451
Default

I think it means horrible little men are invading your privacy.

On no wait, you didnt ask "Whats this govt all about" did you?

__________________
.
"Computers are great! Not for communicating tho. They have one fundamental flaw ... they don't have eyebrows."
AlpineCarStereo: you win ....... eeerrr ..... ummm ..... my undying support of you, the greatest Mod this forum has ever known. My Leige. davepreston: i bow to your modding godliness. vixis: He's this really cute Persian tea-boy, Im so not giving you his number :P
Spiderman is offline   Reply With Quote
Old 25-04-06, 04:57 PM   #10
BILLY
Guest
 
Posts: n/a
Default

stop downloading porn then
  Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Port and... Stingo Idle Banter 5 03-05-08 10:47 PM
Conti Road Attack to Sport Attack glade Tyres 5 03-05-08 02:38 PM
Port Charlotte Richie The Good The Bad and The Ugly Pub and Cafe guide 0 07-10-07 08:52 PM
CT scan this afternoon - hug needed MiniMatt Idle Banter 23 14-09-07 01:34 PM
CCC s/s twin port can pepe SV Talk, Tuning & Tweaking 17 04-05-06 10:14 AM


All times are GMT. The time now is 11:58 AM.


Powered by vBulletin® - Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.