WTH? Installed BlackICE and it tells me I've been scanned 2500 times in 36 hours.

Eug

Lifer
Mar 11, 2000
23,754
1,312
126
I tried ZoneAlarm a while back and it was so damn annoying that I removed it after one day.

I just installed BlackICE for testing, and it tells me that I was scanned 7-8 times while I slept. 2 were "!" and the rest were "?". (For the latter BlackICE tells me I shouldn't worry.)

Is that usual to have that many in such a short period of time?

If it makes a difference, I'm in downtown Toronto on Sympatico DSL (PPPoE), with the computer on 24/7. The IP is not fixed though.

P.S. The computer is also cracking OGR and accessing a keyproxy, so that's the only use of the system when I'm not sitting at it.
 

nateholtrop

Diamond Member
Jun 8, 2000
5,349
0
0
no dont worry about it i also have a network with black ice and zone alarm and I get scanned a bit but not 7 times. dont fret but if it keeps happening ask your isp. Oh do you have an instant messenger? that does it too I have friends that set black ice into coniption fits because they are sending me msg's.

 

BCYL

Diamond Member
Jun 7, 2000
7,803
0
71
I wouldn't worry about it... BlackICE tends to give out a lot of false alarms.... most of those are harmless... Heck BlackICE even gives me warnings when my friend sends me a msg thru ICQ, telling me he is trying to scan my PC...
 

Eug

Lifer
Mar 11, 2000
23,754
1,312
126
Actually the 7 times was probably more like 30... it was 7 unique IP addresses, multiple times each. (I guess it depends on how you count them.)

I left my computer untouched since yesterday except for half an hour in the morning when I posted this topic. What worries me is that I have no ICQ and the computer was completely unused except for it cracking OGR. For OGR, my computer would access the net about 3-4 times. Over the last 24 hour I have been attacked about a thousand times, with over 900 coming from one IP.

Here's my screengrab of BlackICE.

Besides the bunch from Proton, most of the remainder seem to be coming from my ISP (DSL with PPPoE). Can those be ignored?

In the meantime I have set the firewall to the "Nervous" security setting.
 

BCYL

Diamond Member
Jun 7, 2000
7,803
0
71
OK if it's that many times then you have something to worry about... BlackICE should have recorded that guy's IP or something, run a search at SpamCop and see what comes up... You can also report his activities there....

Also if you want you can install ZoneAlarm again... ZA tends to give less false alarms... so u can see if that's a real threat or just something falsely reported by BlackICE...

But if there are over 900 reports within 24 hrs, I highly doubt it's a false alarm
 

Z_Amon

Member
Oct 10, 1999
122
0
0
A lot of those "probes" look like people's computers looking for other computers for sharing. I would suspect that your ISP isn't filtering their network very well and that your network neighborhood is huge. (this is in reference to the NetBIOS connections with various computer names)

Some of them, however, might be more dangerous. If you've had 900...I'll agree with the others, that means that somebody is probably probing you pretty hard, which is typical on that sort of network. If it continues, and there are just a couple of IP's it's from, definitely complain.

Z
 

Eug

Lifer
Mar 11, 2000
23,754
1,312
126
Well, PROTON is back. He has scanned me roughly 2400 times total now. I have since blocked his IP, and have changed my IP address. (I'm on Sympatico DSL which uses dynamic IPs.)

I guess this is another reason NOT to get @Home when I move. Around here my friends who have gotten Rogers@Home have gotten fixed IPs, despite the fact they are told that it uses dynamic ones. I used to think this was a bonus, but now I think it's a liability for casual users like me who do not host anything.
 

barebottoms

Senior member
Mar 26, 2000
508
0
0
Geeze .. Just looking at your screenshot is reason NOT to use Cable at all. Netbios doesn't route, yet you see all those Netbios sessions. You must be good friends with 50 million of your network neighbors.

I realize they are bridging, but geeze.. do some filtering at the cable concentrator.

Look at that, PRONTO might be someone's print server. See if you can attach to it and print them dirty messages.
 

Eug

Lifer
Mar 11, 2000
23,754
1,312
126
barebottoms,

I'm actually on DSL. I was just thinking that maybe it would be even worse on cable.
 

hymy

Senior member
Oct 12, 1999
535
0
76
I'm on charter@home I use Zone alarm on one computer. I've found my cable access to be fairly secure. And my Ip is fixed. very few problems. Bout the only thing I ever get are HTTP servers checking connections. I turned zone alarm down a notch, and it won't bother me unless something really bad happens. I think I have had maybe two netbios attempts in the 3 mos since I installed ZA.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |