Re: Port Scans

From: Mike (spamlessmike@spamcop.net)
Date: 02/24/03


From: Mike <spamlessmike@spamcop.net>
Date: Mon, 24 Feb 2003 15:59:40 GMT

On Mon, 24 Feb 2003 08:24:29 GMT, "Amnesia" <mung@somewhere.notvalid>
wrote:

>I only had one time I was suspicious of some port scans.
>It was one after another, I just disconnected from the Net, and reconnected.
>I received about 300 hits in about or around 20-30 minutes. I didn't note
>the exact time it started. But I was just curious about something. Had
>they of broken in (they didn't) Wouldn't it been the thing to do is to just
>disconnect from the net, and run a Trojan scan to be on the safe side? Is
>all of that necessary? Or is their more to it than just that? Or is that a
>bit too much?
>Was my disconnecting from the net for the multi port scans a just reason?
>Should I have done more?
>
>E-mail addy used is invalid to prevent spam.
> Please post a reply/etc
> to the newsgroups I am active in.
>

Ask yourself: Can an outsider penetrate a firewall that has no open
ports?

The answer is no, ... but there are ways to get through the firewall.

Some crackers are persistent, and they're figuring that one day - you
will upgrade, or change something, or have a technical problem. A
weakness may eventually be presented. Since they can't get in through
the firewall as an unsolicited inbound, they can use other means like
email.

What was logged?

Mike