Results 1 to 5 of 5
  1. #1
    Jdawg50's Avatar
    Jdawg50 is offline Anabolic Member
    Join Date
    Aug 2002
    Location
    Mountains
    Posts
    2,189

    Port scan attack

    My McAfee firewall keeps showing this thing called a "port scan attack", What the hell is it?
    I can trace it, but I have know idea what it means. I do a ping or something?
    Help

  2. #2
    arthurb999's Avatar
    arthurb999 is offline Anabolic Member
    Join Date
    Aug 2001
    Location
    USA
    Posts
    2,712
    It is people trying to scan your ports looking for vounerabilities or open ports. That is how you get hacked. It happens all the time though so as long as you have a tight ship you should be alright.

  3. #3
    Jdawg50's Avatar
    Jdawg50 is offline Anabolic Member
    Join Date
    Aug 2002
    Location
    Mountains
    Posts
    2,189
    What does the trace do? the ping?

  4. #4
    CarbonCopy's Avatar
    CarbonCopy is offline Member
    Join Date
    Oct 2001
    Location
    USA
    Posts
    557
    Quote Originally Posted by Jdawg50
    What does the trace do? the ping?
    Traceroute traces the route of UDP packets for the local host (your computer)to a remote host (the person port scanning you). If you run a traceroute it will display the time and location of the route taken to reach its destination computer. Think of a road map showing you what roads you took to reach a certian location. That is basicly what traceroute does, shows you the location the data came from and the path it took to reach you.

    A ping is used to test routed ip connections. It works at layer 3, the network layer of the OSI network model. It will send a packet of data to a specified host and wait for a reply. Some people might use this to see if a computer is online so they can start port scanning or check for connectivity.

    If you are truly worried about the port scan/scans save the port scan logs and send them to your ISP. I wouldn't be real worried about it so long as your anti-virus is up to date and your firewall is running. Unless the same ip is scanning all the time or you see a pattern with the scans I wouldn't worry. Port scanning is very common and in fact legal. If the attacker tries to connect to the open port, and gain access then he is breaking the law.
    Last edited by CarbonCopy; 01-03-2004 at 03:53 AM.

  5. #5
    Sicilian30's Avatar
    Sicilian30 is offline Respected Member
    Join Date
    Sep 2001
    Location
    There is no place like ho
    Posts
    3,688
    Quote Originally Posted by CarbonCopy
    Traceroute traces the route of UDP packets for the local host (your computer)to a remote host (the person port scanning you). If you run a traceroute it will display the time and location of the route taken to reach its destination computer. Think of a road map showing you what roads you took to reach a certian location. That is basicly what traceroute does, shows you the location the data came from and the path it took to reach you.

    A ping is used to test routed ip connections. It works at layer 3, the network layer of the OSI network model. It will send a packet of data to a specified host and wait for a reply. Some people might use this to see if a computer is online so they can start port scanning or check for connectivity.

    If you are truly worried about the port scan/scans save the port scan logs and send them to your ISP. I wouldn't be real worried about it so long as your anti-virus is up to date and your firewall is running. Unless the same ip is scanning all the time or you see a pattern with the scans I wouldn't worry. Port scanning is very common and in fact legal. If the attacker tries to connect to the open port, and gain access then he is breaking the law.
    A very good technical explanation, couldn't have said it better myself. I would do as Carbon says here, but I would not only report it to my own ISP but find out who the person who is hacking you's ISP and send the reports to them. Usually every ISP has an [email protected]
    If you need help tracking down the ISP just find the IP number that the guy is using, go to www.samspade.org and plug that number into IP Address and it will do a reverse DNS for you.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •