Re: Frequnt port scan attacks
- From: Default User <default@xxxxxxxxxxxxx>
- Date: Tue, 16 Oct 2007 15:30:23 -0400
On 15 Oct 2007 13:42:04 GMT, Ken Knecht <kenk6600@xxxxxxxxx> wrote:
The past few days I've been getting multiple 'port scan attack logged'
notices from my Sygate Personal Firewall (version not indicated in doc).
This is unusual. Anyone else seeing this or is someone going through my
ISP's (Nationwide) IP list? Usually I only get a few a week - now I'm
getting a few an hour.
Strange. Comments?
It's not at all unusual to see port scan attempts from the internet. We
get thousands of failed attempts every day on our publicly facing IP
network and they are all blocked and logged. You don't mention what type of
internet connection you have, but assume you have a DSL/ADSL/Cable type
connection with a DHCP assigned IP address. It is not at all unlikely that
you recently updated your IP address with your ISP and the port scans you
are seeing are related to the previous user of that IP address. There are
many other reasons this could be occurring as well, you would need to
provide more specific information such as the source IP addresses, ports,
and protocols being used, number and frequency of scans from the same
address, etc... in order to determine anything more than you are seeing
normal internet traffic.
.
- References:
- Frequnt port scan attacks
- From: Ken Knecht
- Frequnt port scan attacks
- Prev by Date: Re: Leaving computers on after work?
- Next by Date: Re: Frequnt port scan attacks
- Previous by thread: Re: Frequnt port scan attacks
- Next by thread: Re: Frequnt port scan attacks
- Index(es):
Relevant Pages
|