Re: Attack Detected



On 12/19/2006 11:49 AM, something possessed Al to write:
My firewall continually pops up with a little message saying that an attack to some port was detected. It gives me some numbers (like that's supposed to mean something to me) that I don't understand. There's a log with long lists of these "attacks."
Am I supposed to do something with this stuff? How do I find out who the attacker is?
As you can see, I'm not very experienced with firewalls (except for shutting them off).
Al


They're just portscans, nothing really to be concerned about. The long numbers are IP addresses that belong to the computer that's "attacking" you. There should be a way to config your Personal Firewall so that you don't see these alerts (I'm assuming you're probably using ZA or NIS/NPF, since they tend to call portscans attacks), while still keeping the FW protection. Anyway, it's nothing on your computer, if that's what you're wondering, and nothing really to worry about as far as taking action is concerned.

Regards,

Will
.



Relevant Pages

  • porsentry
    ... attacker is scanning ... # IMPORTANT NOTE: You CAN NOT put spaces between your port arguments. ... # On many Linux systems you cannot bind above port 61000. ... # host when an attack is detected. ...
    (linux.redhat)
  • Re: Sokets De Trois v1
    ... folks in newsgroups who behave that way. ... If there were an actual human attacker, stealth mode doesn't really cut much ... > I believed that if a port was in stealth mode, ... >> generating random email addresses is what the worm ...
    (microsoft.public.security.virus)
  • [EXPL] Multiple Vulnerabilities in CISCO VoIP Phones (Additional details)
    ... Multiple Vulnerabilities in Cisco IP Telephones. ... The Cisco 7900 series of phones include a built-in web server on port ... It is conceivable that a dedicated attacker could put ...
    (Securiteam)
  • RE: Port-Knocking vulnerabilities?
    ... Port Knocking is obfuscation and not a security technique. ... It was and is designed not as a security function, but as a channel to hide communications on compromised hosts. ... Subject: Port-Knocking vulnerabilities? ... what an attacker could ...
    (Security-Basics)
  • CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall
    ... Kerio Personal Firewall Replay Attack and Buffer Overflow ... channel for remote administration. ... authentication mechanism for remote administration allows an attacker ...
    (Bugtraq)

Quantcast