Re: ISP keeps connecting to my port 445
From: GJ (no_at_mail.invalid)
Date: 09/28/04
- Next message: Pablo: "monitor outgoing traffic"
- Previous message: GJ: "Re: ISP keeps connecting to my port 445"
- In reply to: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Next in thread: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Reply: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 28 Sep 2004 00:57:06 +0200
Copelandia Cyanescens wrote:
>>Whenever I connect to my ISP *Reliance India Ltd.*, I keep getting incoming
>>connections for port 445 from one of their computers, which my firewall
>>obviously drops. I need to know whether I should do something about this or
>>this is normal.
>
>
> It's not "normal". Port 445 is Win 2K/XP file sharing, but it is a
> direct TCP/IP connection rather than NETBIOS... a nit pick. There is no
> valid reason an ISP might automatically scan this port that I can see,
> outside of some attempt to detect machines on their network that have
> been or could be compromised. It may be they've had a problem and are
> doing just that, but it would seem a little odd to me because known
> viruses like Korgo that use this service to spread do so from other
> ports *to* port 445 as far as I'm aware. I may be mistaken, and it may
> vary from one virus/variant to another. Scanning remote port 445 may
> tell them who is vulnerable, but not who is infected if my memory is not
> faulty...???
I think an ISP would use a honeypot for checking customers. Then you
could also see by the type of connection and the data transferred if the
connecting computer is infected or not.
> I would contact Reliance India. They may be able to offer a valid
> explanation. They may also have a machine(s) infected with something
> like Korgo and not know it. You should block the traffic regardless,
> which as you say your firewall already does. :)
>
You can conntact the ISP, but i think it's a waste of time. Often, you
don't even get a reply. Just look at what ports you need to have open,
and close the rest of them.
GJ
- Next message: Pablo: "monitor outgoing traffic"
- Previous message: GJ: "Re: ISP keeps connecting to my port 445"
- In reply to: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Next in thread: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Reply: Copelandia Cyanescens: "Re: ISP keeps connecting to my port 445"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|