Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old December 5th, 2004, 08:25 PM
beirti's Avatar
beirti beirti is offline
Contributing? HA!
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: In the office...
Posts: 244 beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 17 m 2 sec
Reputation Power: 20
Question Constant Port scans

Hi, I'm using sygte firewall on a dial-up connection. I'm getting constant port scans on my machine whenever I connect. I contacted the ISP and they told me that it was probably a rountine communication by one of their routers... aha... Eircom Ireland for those of you who were wondering what idiots they are.

I know it ain't one of theirs even if it is a mistaken communication because every tim I connect it's a diff IP address thats scanning me. I backtraced them and they all appear to be local (Irish) addresses.

I'm just curious - is it random hackers trying to find an open port and does anyone else encounter this problem?

Reply With Quote
  #2  
Old December 6th, 2004, 04:46 AM
c444l c444l is offline
contains a pressurised widget
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Location: NC USA
Posts: 401 c444l User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 39 m 41 sec
Reputation Power: 6
Send a message via AIM to c444l Send a message via Yahoo to c444l
Quote:
Originally Posted by beirti
I contacted the ISP and they told me that it was probably a rountine communication by one of their routers...

Quite possibly they are right, though this is most likely if it is the same IP.

Quote:
Originally Posted by beirti
I'm just curious - is it random hackers trying to find an open port and does anyone else encounter this problem?


This is possible too.. and yes it happens to everybody who is connected.

Reply With Quote
  #3  
Old December 6th, 2004, 05:43 AM
mitakeet's Avatar
mitakeet mitakeet is offline
Last Day: May 28, 2005
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2003
Location: Maryland
Posts: 4,575 mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 9 h 51 m 4 sec
Reputation Power: 21
There is not much you can do about it. If they dissallow running servers on their IPs (read the fine print in your agreement) then they may be port scanning to find people violating their agreement. On the other hand, it could be someone else (that may or may not be part of their network) probing for vulnerable machines. Since you are using a publicly available IP, anyone in the world who is bored enough can probe your IP for vulnerabilities.
__________________

Left DevShed May 28, 2005. Reason: Unresponsive administrators.
Free code: http://sol-biotech.com/code/.
Secure Programming: http://sol-biotech.com/code/SecProgFAQ.html.
Performance Programming: http://sol-biotech.com/code/PerformanceProgramming.html.

It is not that old programmers are any smarter or code better, it is just that they have made the same stupid mistake so many times that it is second nature to fix it.
--Me, I just made it up

The reasonable man adapts himself to the world; the unreasonable one persists in trying to adapt the world to himself. Therefore, all progress depends on the unreasonable man.
--George Bernard Shaw

Reply With Quote
  #4  
Old December 6th, 2004, 10:06 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
Are these full port scans or certain ports as they may be viruses/trojans (very common)

Reply With Quote
  #5  
Old December 9th, 2004, 02:27 PM
beirti's Avatar
beirti beirti is offline
Contributing? HA!
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: In the office...
Posts: 244 beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level)beirti User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 17 m 2 sec
Reputation Power: 20
Quote:
Originally Posted by juniperr
Are these full port scans or certain ports as they may be viruses/trojans (very common)


Just got 3 scans from the same IP - the 3 scans ran on diff ports:
1433, 1025, 6129, 135 and 3410
139, 3410, 5554, 445 and 1433
135, 1025, 445, 6129 and 139

Is there anything I can use to communicate back to the IP's? I've tried IP messaging but they aren't getting through.

Reply With Quote
  #6  
Old December 24th, 2004, 05:52 AM
SimonGreenhill's Avatar
SimonGreenhill SimonGreenhill is offline
(retired)
Dev Shed God 11th Plane (10000 - 10499 posts)
 
Join Date: Dec 2003
Location: The Laboratory
Posts: 10,101 SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)SimonGreenhill User rank is General 5th Grade (Above 100000 Reputation Level)  Folding Points: 4925 Folding Title: Novice Folder
Time spent in forums: 3 Months 3 Weeks 5 h 49 m 4 sec
Reputation Power: 1331
Facebook
These all look like vulnerability scans.
eg:
6129 is a port for DameWare (some software with known vulns).
135 is the entry port for a number of RPC worms like Blaster & Lovesan.
3410 is probably a backdoor called 'OptixPro'
1433 is a MS SQL Server port. Lots of nice security holes there.

Some script kiddie is just scanning you. No big deal.

Reply With Quote
  #7  
Old January 8th, 2005, 01:39 PM
teki associates teki associates is offline
Retired
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 252 teki associates User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 30 m 20 sec
Reputation Power: 5
Exclamation

This activity is probably by bots/worms on compromised machines. Best thing you can do is not worry about it as long as uve secured you computer. The traffic will be coming from all over the place and you can't do a thing (unless you disconnect entirely from the net.)
Now you know why it only takes 4 minutes for a windows computer without a firewall to be infected. Your computer without a firewall would soon be attacked and be used to attack others/send spam.

Reply With Quote
  #8  
Old March 8th, 2005, 04:02 PM
webstuff webstuff is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 16 webstuff User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 34 m 52 sec
Reputation Power: 0
Question 1433 MS SQL port security holes

you mentioned MS SQL 1433 port security holes...
what kind of holes do you know exist and how can I fix it?
is it recommended to run MS SQL server with a different port than the standard 1433?
thanks.

Reply With Quote
  #9  
Old March 8th, 2005, 05:21 PM
mitakeet's Avatar
mitakeet mitakeet is offline
Last Day: May 28, 2005
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2003
Location: Maryland
Posts: 4,575 mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 9 h 51 m 4 sec
Reputation Power: 21
There is no reason to have any database directly accessible via the Internet, so any perimeter firewall should block UDP/TCP 1433. You can change the port, btw, but it should still be hidden behind a firewall.

Reply With Quote
  #10  
Old March 9th, 2005, 02:03 AM
webstuff webstuff is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 16 webstuff User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 34 m 52 sec
Reputation Power: 0
SQL access from outside

Quote:
Originally Posted by mitakeet
You can change the port, btw, but it should still be hidden behind a firewall.


but what if I want to allow the SQL users access from outside using tools like enterprize manager ?
Am I making it easy for hackers by allowing this option?

Reply With Quote
  #11  
Old March 9th, 2005, 05:34 AM
mitakeet's Avatar
mitakeet mitakeet is offline
Last Day: May 28, 2005
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2003
Location: Maryland
Posts: 4,575 mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 9 h 51 m 4 sec
Reputation Power: 21
Your users should be using some sort of VPN or terminal server (via an encrypted link). I am pretty sure that enterprise manager communication is unencrypted (though I believe the authentication is encrypted), which almost certainly makes it subject to hijacking and it is generally accepted that it is reasonably straitforward to elevate privledges of any SQL account to the equivelent of DBO/SA and from there, through the use of the right stored procedures, full 0wnership of the machine.

It is your network, though.

Reply With Quote
  #12  
Old March 13th, 2005, 05:34 AM
c444l c444l is offline
contains a pressurised widget
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Location: NC USA
Posts: 401 c444l User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 39 m 41 sec
Reputation Power: 6
Send a message via AIM to c444l Send a message via Yahoo to c444l
Wow.. I had forgotten all about this thread.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Constant Port scans


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |