Port Scanning, a little help please

TheLoot

Senior Member
Joined
Dec 19, 2006
Messages
966
Reaction score
9
Location
Cape Town
I have Comodo firewall, and for the past 6 hours (straight, every 5 or 10 seconds) I have been getting "Inbound Policy Violations" from an IP which resolves to a Telkom ADSL IP (comparing with IP's obtained on international and local accounts, it's an international account).

This entity keeps on trying to get in on port 1194. Always port 1194 on my side that they trying to exploit. The funny thing is, (maybe not so funny, I have no idea what this person is doing) is that on thier side, the port they are using to scan my port 1194 is increasing. So one scan will be from <freak>:50000 to <me>:1194 the next from <freak>:500001 to <me>:1194 where <freak> represents the IP of the scanner and <me> is my (local SAIX) IP.

It seems like some sort of scan, but it doesn't make sense to me that the ports on thier side is increasing; if they were scanning me wouldn't the ports on my side be changing ?!

If anyone knows what this is, please let me know :)
 
port 1194 is usually OpenVPN's port. And it's UDP based, so some computer is broadcasting the entire subnet looking for responses.
It's probably a badly configured OpenVPN setup.

The internet is full of these things.
 
Yeah, you probably had an IP that was hosting a VPN at some stage, and that's just a client trying to reconnect, as they haven't discovered the new one yet.
 
I have been getting "Inbound Policy Violations" from an IP which resolves to a Telkom ADSL IP
That is network abuse and you should really log a call with SAIX's abuse desk otherwise it will never stop and it could start chewing up your bandwidth.

SAIX have been know to suspend accounts for this sort of thing and that usually provides a decent incentive for the person to get their system fixed :D
 
...also sometimes you get ppl ( wannabe hackers ) that uses "canned" software to scan a range of ports...If it ONLY scans port 1194, i doubt it to be serious :)
 
The weird increasing port numbers are nothing to worry about. I've seen the same thing on my PC, also with Comodo.

If the blogs24 site is open, it keeps sending small bits of info to the blogs24 site. On my side, the port numbers are always increasing by one, while the destination port # is constant. When I close the blogs24 tab, it stops.

I'd say its not port scanning, but rather some noob toying with a VPN.

Oh, and if there is really a portscan, then Comodo will automatically tighten the rules. Configure under Advanced==>Advanced Attack Detection and prevention.:)
 
Top
Sign up to the MyBroadband newsletter
X