India Broadband Forum


port scan attack

This is a discussion on port scan attack within the Computer Security forums, part of the Computer technology category; well can it be stopped?? or can i take any legal actions against the holders of the ip addresses from ...

Go Back   India Broadband Forum > Computers > Computer technology > Computer Security

India Broadband Forum


                      

Reply

 

LinkBack Thread Tools Display Modes
Old 04-27-09, 09:53 PM   #1
Junior Member
 
Join Date: Nov 2008
Location: Kolkata
Posts: 91
Rep Power: 2
saugatdb is on a distinguished road
Default port scan attack

well can it be stopped?? or can i take any legal actions against the holders of the ip addresses from which the attacks are coming??
saugatdb is offline   Reply With Quote
Old 04-27-09, 10:45 PM   #2
Gold Member
 
Logik's Avatar
 
Join Date: Jan 2008
Location: On Internet
Posts: 680
Rep Power: 5
Logik is a jewel in the roughLogik is a jewel in the roughLogik is a jewel in the roughLogik is a jewel in the rough
Send a message via MSN to Logik Send a message via Yahoo to Logik
Default

well if u can post some more details of the problem ur facing, that will be really nice. like the ips attacking u? since when ur facing the problem? Which Firewall ur using?

also tell me if ur having dynamic or static IP?

also notice one thing, sometimes, if a computer system is affected too much by a port scan, one can argue that the port scan was, in fact, a denial-of-service (DoS) attack, which is usually an offense.

there are certain online tests available to scan ports. google them
Logik is offline   Reply With Quote
Old 04-27-09, 10:50 PM   #3
Gold Member
 
skap's Avatar
 
Join Date: May 2008
Location: India
Posts: 531
Rep Power: 2
skap will become famous soon enough
Default

Yes you can submit them to abuse teams with logs. After you find that w.x.y.z IP is doing port scan on your network, login to dns record sites such as Free online network utilities - traceroute, nslookup, automatic whois lookup, ping, finger and find the owner of that IP address. ( Go to this site, choose Domain Dossier and enter that attacker IP w.x.y.z. This provides you contact and owner information of that IP.) If you scroll down in that page, you can find an email id to report any abuse activity. Send report to that email id.
Otherway is, you can submit to other abuse teams like dsheild

How to protect?
Port scanning can be blocked in so many ways.

1. Simple solution is by effectively configuring your Windows Firewall. Firewall configuration tips is provided here http://www.indiabroadband.net/comput...-firewall.html (what is port and program exception in Firewall?)

2. You can also see in Sygate Online Services, which provides online security threat scanning report of your computer. This report will say whether your computer is compliance with recommended basis security standard. When I checked, the scan checks for highly vulnerable open ports and not all ports.

3. There are some free valuable Firewalls available that can completely hide your computer from outside world. They help to run your computer in stealth mode. Some firewalls are ZoneAlarm & Comodo Firewall.

Last edited by skap; 04-28-09 at 01:04 AM.
skap is offline   Reply With Quote
Old 04-28-09, 02:49 AM   #4
meetdilip
Guest
 
Posts: n/a
Default

You can download these firewalls here.
  Reply With Quote
Old 04-28-09, 05:26 AM   #5
Junior Member
 
Join Date: Nov 2008
Location: Kolkata
Posts: 91
Rep Power: 2
saugatdb is on a distinguished road
Default

ok the thing is the ips from which i m getting the attacks are not same, when i checked them i found that they are from many countries(some of them are bsnl ips). im facing this problem from 2-3 weeks & i m using eset smart security 4.0 & i m a bsnl user so i got dynamic ip.

@skap
tested my compu @ sygate
results attached
Attached Images
File Type: jpg log.JPG (81.1 KB, 11 views)
File Type: jpg sygateres.JPG (27.3 KB, 10 views)
saugatdb is offline   Reply With Quote
Old 04-28-09, 03:59 PM   #6
Gold Member
 
skap's Avatar
 
Join Date: May 2008
Location: India
Posts: 531
Rep Power: 2
skap will become famous soon enough
Default

Does your antivirus find any Trojan horse or worm in your computer? your computer might be infected.
Also monitor outgoing traffic from your computer to Internet.
skap is offline   Reply With Quote
Old 04-28-09, 04:17 PM   #7
Junior Member
 
Join Date: Nov 2008
Location: Kolkata
Posts: 91
Rep Power: 2
saugatdb is on a distinguished road
Default

nop no virus or trojan is present in my comp. , i also regulary monitor my outgoing traffic & i dint found anything suspicicous
saugatdb is offline   Reply With Quote
Old 04-28-09, 04:59 PM   #8
Gold Member
 
skap's Avatar
 
Join Date: May 2008
Location: India
Posts: 531
Rep Power: 2
skap will become famous soon enough
Default

because the port 6000 is used by Trojan horse/worm to communicate. What AV do you use?
skap is offline   Reply With Quote
Old 04-28-09, 05:01 PM   #9
Gold Member
 
Join Date: Jun 2008
Location: Where I am
Posts: 579
Rep Power: 5
sujithsukrutham is just really nicesujithsukrutham is just really nicesujithsukrutham is just really nicesujithsukrutham is just really nice
Send a message via Yahoo to sujithsukrutham
Default

Quote:
Originally Posted by saugatdb View Post
nop no virus or trojan is present in my comp. , i also regulary monitor my outgoing traffic & i dint found anything suspicicous
As per your anti virus......Try some other
sujithsukrutham is offline   Reply With Quote
Old 04-28-09, 05:53 PM   #10
meetdilip
Guest
 
Posts: n/a
Default

Monitoring outgoing traffic is not easy. In my system when I initiate any program, svchost.exe access trusted area or internet and start downloading spyware. If you block it, you cannot access internet as there is another original svchost.exe which allows you to connect to internet. My system was hijacked, I fixed it and using my experience to block svchost.exe and other disguised files to prevent malware.

Time has long gone when you install an antivirus in your system and when it says your system is ok, it is so. If we know this much, imagine the kind of stuff hackers are made of.

Even with firewall we are not safe. Experience is the name man gives to his mistakes.
  Reply With Quote
Old 04-28-09, 09:00 PM   #11
Bronze Member
 
Jaganathsamal's Avatar
 
Join Date: Dec 2008
Age: 17
Posts: 170
Rep Power: 1
Jaganathsamal is on a distinguished road
Default

All you can do is try using a good firewall to stop port scan & keep ur pc updated. Do check for viruses/malwares since they can even fool good antiviruses & other security softwares easily. There are simple methods to bypass firewalls too , so monitor ur outgoing & incomming traffic ( & data usage).
Jaganathsamal is offline   Reply With Quote
Old 04-28-09, 09:06 PM   #12
Platinum Member
 
Join Date: Aug 2007
Location: Chennai
Posts: 4,225
Rep Power: 12
essbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of light
Default

From Post 1.
Quote:
well can it be stopped?? or can i take any legal actions against the holders of the ip addresses from which the attacks are coming??
sorry . did not read the thread fully.
Probably you are using torrents to download .
or in Email ?

could be some repetition in my post.




If you know the Ip address check location/country.
IP2Location.com - Lookup IP address to Country, State, City, Netblock, Longitude and Latitude

Go to filehippo.com and select any FREE AV and firewall applications. ( about 10 each available )

"PREVENTION IS BETTER THAN CURE"
essbebe is offline   Reply With Quote
Old 04-29-09, 06:46 AM   #13
Junior Member
 
Join Date: Nov 2008
Location: Kolkata
Posts: 91
Rep Power: 2
saugatdb is on a distinguished road
Default

Quote:
Originally Posted by skap View Post
because the port 6000 is used by Trojan horse/worm to communicate. What AV do you use?
ESET smart security 4.0

Quote:
Originally Posted by meetdilip View Post
Monitoring outgoing traffic is not easy. In my system when I initiate any program, svchost.exe access trusted area or internet and start downloading spyware. If you block it, you cannot access internet as there is another original svchost.exe which allows you to connect to internet. My system was hijacked, I fixed it and using my experience to block svchost.exe and other disguised files to prevent malware.

Time has long gone when you install an antivirus in your system and when it says your system is ok, it is so. If we know this much, imagine the kind of stuff hackers are made of.

Even with firewall we are not safe. Experience is the name man gives to his mistakes.
ok i will try to figure it out

Quote:
Originally Posted by essbebe View Post
From Post 1.

sorry . did not read the thread fully.
Probably you are using torrents to download .
or in Email ?
could be some repetition in my post.

If you know the Ip address check location/country.
IP2Location.com - Lookup IP address to Country, State, City, Netblock, Longitude and Latitude

Go to filehippo.com and select any FREE AV and firewall applications. ( about 10 each available )

"PREVENTION IS BETTER THAN CURE"
well i dont use torrents for dwnload only from RS , i will try some other AV & firewall
saugatdb is offline   Reply With Quote
Old 04-29-09, 10:37 AM   #14
Platinum Member
 
Join Date: Aug 2007
Location: Chennai
Posts: 4,225
Rep Power: 12
essbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of light
Default Audit your system march31st 2009 F/Y ending !!!!

Firewall Test, Web Tools and Free Internet Security Audit

add to book marks.
try the applications listed.
essbebe is offline   Reply With Quote
Old 04-29-09, 12:55 PM   #15
meetdilip
Guest
 
Posts: n/a
Default

@essbebe, thanks for the link

Quote:
Originally Posted by saugatdb View Post
ESET smart security 4.0
well i dont use torrents for dwnload only from RS , i will try some other AV & firewall
RS downloads are not always safe. It has nothing to do with RS but many RS searching sites are not safe. Some of them have malware and if you search for 123fdfjor, they will show result as 123fdfjor 2.3V or 123fdfjor Pro.

Some kind of firewall like to show us they are efficient and would like to show how much they protect you from threats. May be ESET has similar thoughts. Just try Comodo or Zonealarm and check. You can always revert if you don't like.

These are free firewalls but Yahoo and Google are also free. I have already provided you the link. Always use a popular antivirus pack. Reporting of new threats will be more efficient in popular softs.

Last edited by meetdilip; 04-29-09 at 03:01 PM. Reason: Automerged Doublepost
  Reply With Quote
Old 04-29-09, 02:45 PM   #16
Gold Member
 
skap's Avatar
 
Join Date: May 2008
Location: India
Posts: 531
Rep Power: 2
skap will become famous soon enough
Default

can you post results of "netstat -an |more" command?

before that close all your connections, say browser, messenger, emails espcially torrents and let Internet work!

This command will tell you
* Connections established in your computer to remote host
* all open ports in your computer and
* all listening ports in your computer
skap is offline   Reply With Quote
Old 04-29-09, 04:47 PM   #17
Junior Member
 
prakash_mvpa's Avatar
 
Join Date: Jan 2009
Location: Kerala
Age: 30
Posts: 21
Rep Power: 1
prakash_mvpa is on a distinguished road
Default

hello ,
If your work doesnot insist on windows operating system ,why not try a Linux distro like Ubuntu?much safer.moreover ,iptables can be configured for complex options using frontends like shorewall.
try Ubuntu ,if you are a Desktop Home user.Else for security ,Debian GNU/Linux is better.
ubuntu(dot)com
and
debian(dot)org

Good Luck!
prakash_mvpa is offline   Reply With Quote
Reply

Tags
attack, port, scan

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
System restarts during Virus Scan pls help meetdilip Computer Security 66 04-28-09 06:01 PM
virus attack ! cheeru Computer Security 16 04-07-09 03:33 AM
Attack By The Savage rupu1983 News discussions 9 02-09-09 08:00 PM
MTNL Network Scan buntyindia MTNL broadband 0 06-22-08 10:00 PM
can i scan my computer through my laptop? player Computer hardware and software tips and tricks 2 03-29-08 08:46 PM


All times are GMT +5.5. The time now is 09:58 AM.


India Broadband Forum