I think some body is running a port scan on my computer, darn kiddie hackers!

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
I got home and my zonealarm alert log was at it's max, meaning it had blocked over 500 attempts to access my computer. I cleared the log. Guess what, 5 minutes later it had blocked over 500 again. Somebody is busting there nuts trying to get in, another 170 more attempts since I started typing...
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
Ok, they're a ton of different IPs trying to access one single port on my system, does that mean anything?

<EDIT>
Just broke 350 since I posted...
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
nah, the FBI would have tried other ports by now, whoever is doing it should have learned that port is blocked. Not that bright but sure as hell persistant...

Over 1000 blocked requests since I posted....
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
I bet you were somehow linked from some other site. Which port is it? You could be listed as a proxy or some such noncense.

Armani
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
there's a bunch of them...
213.237.69.3
216.232.95.41
12.216.1.3
213.187.180.178
143.105.22.173

I've been looking over the log, I can't find any repeats though. the log of all the alerts has gone from about 100k from the time I turned on my computer till I went to school this morning. It's now over 1199k. If you want it I can send it, it lists IPs, the ports they're using etc.. etc...

I've now blocked well over 2000 attempts.
 

rgwalt

Diamond Member
Apr 22, 2000
7,393
0
0
It sounds like you are being hammered by a bunch of script kiddies. Have you pissed anyone off lately? Maybe in CS or something like that?

Ryan
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
Lol. You guys are so paranoid. That is the Kazaa port. Chances are those guys are trying to download something off of you Close your P2P program maybe?

Armani
 

atrowe

Banned
May 20, 2001
253
0
0
Port 1214 is Kazaa. Did you have a Kazaa client running while you were gone? It's most likely people trying to establish downloads from your Kazaa shared folder. I would reconfigure Zonealarm to allow requests for port 1214.
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
Doesn't matter. Maybe you're on their SuperNode list. Maybe you have a large file that they realy want to continue on your server. Botom line: Don't immediatly blame those crackers for every little hickup your system has. You have no idea how many people have wanted me to fix their computer cause they were hacked. Ha! Them deleting their own windows folder does not constitute a hack.

If someone is attacking you, using port 1214 is the most inefficent way of doing it I have ever heard.

Armani
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
I don't have kazaa installed, I know grokster uses the kazaa network, but I have no trouble using that.
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
Liste, 1214 is the same port that grokster uses. It would be better said that the FastTrack network uses that port.

The reason you can still get things from other people is that you can ask them to send to your open packet stream. Likewise, the others can DL off of you because instead of conecting to you, the request a "push" from you, and your computer will automaticaly send it to them, instead of the other way around.

Realy, you are safe. You're not going to die.

Armani
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Damn you all crack me up!!

It's funny to see many reference "script kiddies" when you don't even know what's really going on. First off, a port scan is not an intrusion attempt! You weren't even port scanned! A scan is just that, a scan, not an attempt to connect to a single port. The fact that it's from a diverse # of ips should have told you they were looking for a service.



<< nah, the FBI would have tried other ports by now, whoever is doing it should have learned that port is blocked. Not that bright but sure as hell persistant... >>



No offense, but ahhhhh.... the irony

[edit]Technical clarification: One may scan a subnet looking for a particular port on each host, so an attempt to connect to a single port could indeed be a scan, but the fact that you received the same connection attempt from many other ips suggests that it's not.[/edit]
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |