Re: Decrease in 1433 Scans?

From: MIS Department (mis@newnanutilities.org)
Date: 05/23/02


Date: Thu, 23 May 2002 13:22:24 -0400
To: incidents@securityfocus.com
From: MIS Department <mis@newnanutilities.org>


>Access attempts to port 1433 have been steady all this week, with tons of
>attempts every hour showing up in our firewall log; however, I have not
>had a single attempt since 5:43 AM EST (no EDT here in Indiana).
>
>The firewall is still logging and the integrity of my access-list appears
>to be fine. I doubt our uplink provider is doing this, as I can reach the
>firewall if I attempt to connect to port 1433 with nmap from a remote
>system.
>
>Anyone else seeing this?

It's still pretty steady here, right this moment especially from
216.62.5.226 & 216.195.183.6.

Brian Collins
Systems Administrator
Newnan Utilities

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Port 31336 question
    ... After reviewing my firewall log, I've noticed for the last 48 hours that ... someone has been trying port 31336 on my firewall. ... What is with this port. ... Linksys router with SPI On and WAN Request blocked on the router. ...
    (comp.security.firewalls)
  • Re: [SLE] Firewall and port 5353 (mdnsd)
    ... > Looking up port 5353 I see that this is used by the Multicast DNS daemon ... > be configured in a way that the firewall log is swamped with these messages ... > but I am not sure if opening up port 5353 in the firewall is a good thing. ...
    (SuSE)
  • Re: cant remote connect to mailman on panther server
    ... where adminport is 80 or whatever the mailman ... > But I don't know for sure that mailman is on port 80 ... > I just tried it with the firewall off - it DOES WORK then. ... > But it would appear the firewall log is lying, or else I can't read, or ...
    (uk.comp.sys.mac)
  • Decrease in 1433 Scans?
    ... attempts every hour showing up in our firewall log; ... The firewall is still logging and the integrity of my access-list appears ... firewall if I attempt to connect to port 1433 with nmap from a remote ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)