Port Scan Attack Help...

hj2k_x

Honorary Master
Joined
Jan 22, 2006
Messages
32,137
Reaction score
1,893
Location
/\/¯¯¯¯¯\/\
My firewall keeps alerting me to the fact that my ports are being scanned- I take it this is not good! What can i do to stop it?
 
My firewall keeps alerting me to the fact that my ports are being scanned- I take it this is not good! What can i do to stop it?

Thats the Good part... when your firewall doesnt report it, then its bad. But being port-scanned is a fact of life on the internet. either disallow all ports and make sure that if there is a web server on your network, its secured.
 
It has only started today. Hasn't reported anything like that until now. What does port-scanning actually do and who would want to do it? Hackers?
 
Hackers or bored kids looking for open ports to have a little looksy at your pc

So it is as bad as that? How do I know if they find anything or look at anything once they have scanned my ports? What kind of info can they gather? And is there no way of ensuring this doesn't happen or sending them a big **** OFF right back??
 
It looks like your firewall is doing its job just watch for weird activity or cycle power on your router/modem to grab a new IP.
 
So it is as bad as that? How do I know if they find anything or look at anything once they have scanned my ports? What kind of info can they gather? And is there no way of ensuring this doesn't happen or sending them a big **** OFF right back??

You can make life difficult for them by using a Tarpit or an active firewall (one that blacklists an IP if it detects bad behaviour) - or switch your ADSL off for 10 minutes and get a new IP number. All you need to do is make sure your firewall is watertight.
 
You can make life difficult for them by using a Tarpit or an active firewall (one that blacklists an IP if it detects bad behaviour) - or switch your ADSL off for 10 minutes and get a new IP number. All you need to do is make sure your firewall is watertight.

ok, will check out this tarpit business...
 
Go to grc.com and try sheilds up, as long as you have no open ports.

Port scanning is like unknown people knocking at your door and you're just not answering.
 
If you're on ADSL and using a router make sure your computer isn't set as the DMZ, if it's not then your router should block a lot before it even gets to your PC firewall.
 
If you're on ADSL and using a router make sure your computer isn't set as the DMZ, if it's not then your router should block a lot before it even gets to your PC firewall.

I am using routesentry and dialing into my connections via raspppoe, so the router is in bridge mode...
 
Port scanning is not necessarily an "Attack"

Scanning yourself from grc and the like is a good idea, but I have just seen a possible problem which it does not show you.

I was just now checking my own setup, when I mistyped the IP and stumbled over a Win2k server connected to an IP address close to mine. It seems to be totally unprotected, and I can see printer and disk shares without even a password. I did not try to connect. Ports 135 and 139 are open to the adsl subnet from this box, but they are closed when I look from another point on the Internet, so grc would not see them. I guess the ISP filters them, correctly IMHO.

I suppose this saga happens all the time, so I came here looking for advice.

I would like to try to locate and tell the user, but my inclination now is just to tiptoe away, particularly since it seems from what I read here that using a port scanner, which is what I was doing, seems to be taken even by well-informed people as prima facie evidence of nefarious intent.

I think that is bull, there are plenty of legitimate reasons to scan, but I have read too many stories where guys trying to be helpful wind up getting arrested as 'hackers', and I don't want to get to argue about it in a clueless court.
 
Disconnect and reconnect. It might be that someone before, who had your current ip was insecure and so there was control over their computer.
 
I think that is bull, there are plenty of legitimate reasons to scan, but I have read too many stories where guys trying to be helpful wind up getting arrested as 'hackers', and I don't want to get to argue about it in a clueless court.

What legitimate reasons are there to scan other people's IPs?
 
Top
Sign up to the MyBroadband newsletter
X