Getting slammed from port 12200

Chaotic42

Lifer
Jun 15, 2001
33,932
1,113
126
So every once in a while I log into my OpenBSD firewall to see what's been going on. Today I noticed that I have been getting *slammed* by computers mostly in the 221.x.x.x IP range and always on port 12200. I looked up the IP range and it's from Asia, and port 12200 appears to be something SAN related.

I mean this thing is going nuts. All kids of different IP addresses, mostly in the same 221 range. Here's a sample:

Code:
15:11:12.000456 221.1.220.199.12200 > CHAOTIC42IP.2479: S 1966153762:1966153762(0) win 8192 (DF)
15:11:12.306937 221.1.220.199.12200 > CHAOTIC42IP.9090: S 1966213044:1966213044(0) win 8192 (DF)
15:11:12.564609 221.1.220.199.12200 > CHAOTIC42IP.8090: S 1966272326:1966272326(0) win 8192 (DF)
15:11:12.671603 221.1.220.199.12200 > CHAOTIC42IP.1080: S 1966301967:1966301967(0) win 8192 (DF)
15:11:13.489275 221.1.220.199.12200 > CHAOTIC42IP.8118: S 1966420531:1966420531(0) win 8192 (DF)
15:11:13.661051 221.1.220.199.12200 > CHAOTIC42IP.8088: S 1966450172:1966450172(0) win 8192 (DF)

There are tons of these things. 231 in the last four hours and ten minutes. They're also pinging me.

Any idea what this is or anything I can do about it?
 

Bandit1

Member
Jan 11, 2005
105
0
0
Same port scans hit me awhile back on 12200.They were all china addys.It did NOT stop for a week and would've kept on.Blocked chunks of ip's,then they just switched up.I'd recommend aquiring a new ip address and a few cosmetic router changes if it really gets bothersome or worrysome.
 

Modelworks

Lifer
Feb 22, 2007
16,240
7
76
When this happens and it is persistent what you need to do is find the address that they are connecting to in the USA from their provider. Then copy the logs and send it to the network provider that they are using for that connection. If you are lucky it will be a decent provider and they will block the traffic.

The problem with things like this is people rarely do any reporting of it and just ignore it so it continues. Network providers really don't want this kind of traffic and will stop it if notified.

Same for malware. I report every instance I find of a server distributing it. I think people might be surprised at how often I get an immediate response from the provider telling me they have fixed the situation. If you don't report it , it will continue.

when I trace back to that address is seems they are using qwest for the connection point in the USA. To contact them it would be abuse@qwest.net
 
Last edited:

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
Modelworks hit the nail on the head, but to answer your second question regarding pings.

Create a rule (I'm assuming you are using iptables in BSD?) that discards all ICMP traffic on the WAN Side.

Bandit1 - I'm not sure how you think you can just change IP Addresses on a whim. Unless you purchased a large block of Private WAN Side IP's from your ISP (Highly unlikely) you are likely on a Dynamic IP scheme that will change every once in a while.
 

Bandit1

Member
Jan 11, 2005
105
0
0
Bandit1 - I'm not sure how you think you can just change IP Addresses on a whim. Unless you purchased a large block of Private WAN Side IP's from your ISP (Highly unlikely) you are likely on a Dynamic IP scheme that will change every once in a while.

I only speak from experience,as little as i post here i could care less if you believe it.I sure as hell CAN,on a "whim"as you say change my dynamic ip..Look around a bit,experiment.It can take some patience to nail it.The more methods of defense at your disposal,the better off you are.This does'nt mean running 10 quadzillion programs,either.That's all i've got to say.I stand by my thoughts providing certain situations arise,such as above.
 

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
I only speak from experience,as little as i post here i could care less if you believe it.I sure as hell CAN,on a "whim"as you say change my dynamic ip..Look around a bit,experiment.It can take some patience to nail it.The more methods of defense at your disposal,the better off you are.This does'nt mean running 10 quadzillion programs,either.That's all i've got to say.I stand by my thoughts providing certain situations arise,such as above.

You do not have control when your ISP switches your IP Address. You can release and renew the lease until your fingers fall off - if the ISP's rule dictates the IP's re-lease every week, you have to wait until that time is up!
 

sldysart

Junior Member
Apr 7, 2011
1
0
0
I was getting annoyed with recurring port scans and wanted to get a new IP address without leaving my network shut down for a couple days. This worked for me on Charter:

Clone the MAC address of a connected PC to the router, shutdown and restart modem & router. I immediately got a new IP address. Leave in place several days until the lease associated the original MAC address has expired. Then, if you want, you can switch the MAC address back.
 

LiuKangBakinPie

Diamond Member
Jan 31, 2011
3,903
0
0
does your firewall accept incoming echo requests?
This is what happening
Google for this ->yersinia

For INBOUND packets the Destination Port isthe port on YOUR computer! The Source Port is the port on the computer where the packet originated. So the scans in your first entries were to destination Port

These are probes looking for specific vulnerabilities, and yes everyone sees them. You can look up the IPs on www.mynetwatchman.com and see that these IPs are probing other users also.
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |