Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 04-22-2004, 12:57 PM   #1
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
Question Attack before connecting to internet?

My firewall registered an attack from an IP before I connect to the internet & I have not even begun connecting. What does this mean?
Using sygate personal firewall.
__________________
CPU: Intel E-5200. Graphics: Saphire Radeon 4770 HD 512 MB. Motherboard: Gigabyte GA-EP43-DS3L. Memory: Corsair XMS2 Xtreme Performance 4 GB ( 2 x 2 GB ), Chasis: Antec Three Hundred. PSU: Corsair CX400W. Optical Drive: Sony Optiarc SATA DVD +-RW. Storage: Seagate Barracuda 7200.12 500GB SATA. Peripherals: Dell E1905EP 19" UltraSharp LCD; LG M227WD (Dual screen), HP 4180 Printer, Canon S400SP Printer & Lide20 Scanner; Philiphs HP 890, Edifier MP230. OS: Win 7 (64 bit). Laptop: Toshiba Satellite M50
mystvearn is offline   Reply With Quote
Old 04-22-2004, 01:46 PM   #2
Member (11 bit)
 
Blue_Gundam2002's Avatar
 
Join Date: May 2003
Location: Houston, Texas
Posts: 1,340
Send a message via AIM to Blue_Gundam2002 Send a message via Yahoo to Blue_Gundam2002
Are you on a lan? It might just be picking up lan trafic.
Blue_Gundam2002 is offline   Reply With Quote
Old 04-22-2004, 04:42 PM   #3
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
What you see as an attack is very often legitimate traffic, you have to analyze what it's telling you, not just assume someone is hammering you.

I have alerts turned off in ZA, and hardly ever look at the log - I just let the firewall do its job. If an app wants access and it's not already preapproved by me, it will still ask.

Last edited by glc; 04-22-2004 at 04:45 PM.
glc is offline   Reply With Quote
Old 04-22-2004, 09:26 PM   #4
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
No. I ahve broadband-DSL. Before I went offline, I see the same P attacking. & just as I wanted to enter the internet after restart, the same IP attacking me agan.
mystvearn is offline   Reply With Quote
Old 04-22-2004, 10:10 PM   #5
Member (11 bit)
 
Blue_Gundam2002's Avatar
 
Join Date: May 2003
Location: Houston, Texas
Posts: 1,340
Send a message via AIM to Blue_Gundam2002 Send a message via Yahoo to Blue_Gundam2002
Quote:
Originally posted by mystvearn
No. I ahve broadband-DSL. Before I went offline, I see the same P attacking. & just as I wanted to enter the internet after restart, the same IP attacking me agan.
Whats the IP thats attacking you?
Blue_Gundam2002 is offline   Reply With Quote
Old 04-22-2004, 10:12 PM   #6
Member (9 bit)
 
TeenPcknowit's Avatar
 
Join Date: Mar 2004
Location: Pittsburgh,PA
Posts: 319
Send a message via AIM to TeenPcknowit
Lol yeh, let us have some fun with this IP...
TeenPcknowit is offline   Reply With Quote
Old 04-22-2004, 11:00 PM   #7
Member (11 bit)
 
Blue_Gundam2002's Avatar
 
Join Date: May 2003
Location: Houston, Texas
Posts: 1,340
Send a message via AIM to Blue_Gundam2002 Send a message via Yahoo to Blue_Gundam2002
Quote:
Originally posted by TeenPcknowit
Lol yeh, let us have some fun with this IP...
No, I'm being serious. We can find out if it's known to be used in attacks or if its just his modem or router sending feedback to his computer. I had zone alarm a while back and it would say my modem was trying to attack me when it was just checking for activity.

Last edited by Blue_Gundam2002; 04-23-2004 at 12:26 AM.
Blue_Gundam2002 is offline   Reply With Quote
Old 04-23-2004, 12:03 AM   #8
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
Teen - we don't behave like that around here.

- Moderator -
glc is offline   Reply With Quote
Old 04-23-2004, 01:27 AM   #9
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
The IP is 219.93.197.62. I think nearly 100 attacks from it.
my DSL using dynamic IP.
Sygate says its security type is port scan.
Severity:minor
Direction: incoming

Maybe its my IP?
mystvearn is offline   Reply With Quote
Old 04-23-2004, 09:10 AM   #10
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
Well, I just looked up your IP when you made this post - and it's close enough to make me conclude it's coming from your ISP. They are probably just scanning their customers' ports for unauthorized servers and security issues that would affect their whole network. Either that, or it's another customer running a port scanner.
glc is offline   Reply With Quote
Old 04-23-2004, 11:15 AM   #11
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
Thanks. How did you find that out? I have lots of attacks, coming from 219.93.19(6/7).xxx alot. Maybe its normal. Thanks.
mystvearn is offline   Reply With Quote
Old 04-23-2004, 12:19 PM   #12
Member (9 bit)
 
MulderMan's Avatar
 
Join Date: Dec 2003
Location: England
Posts: 362
Send a message via AIM to MulderMan
i looked it up and appears to be coming from malaysia so i presume its your isp. i use this to look up ips http://ip-to-country.webhosting.info/node/view/36
MulderMan is offline   Reply With Quote
Old 04-23-2004, 02:57 PM   #13
Member (9 bit)
 
TeenPcknowit's Avatar
 
Join Date: Mar 2004
Location: Pittsburgh,PA
Posts: 319
Send a message via AIM to TeenPcknowit
Very sorry, it was intended as a joke.
TeenPcknowit is offline   Reply With Quote
Old 04-23-2004, 10:09 PM   #14
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
Thanks,
mystvearn is offline   Reply With Quote
Old 04-24-2004, 09:54 AM   #15
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
As a moderator, I can look up the IP address of every post. Your IP is 219.93.196.xxx, your ISP is very likely using the 219.93.196.xxx and 219.93.197.xxx subnets.
glc is offline   Reply With Quote
Old 04-24-2004, 11:49 AM   #16
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
I see. All forum mods have this ability? Even from different forums?
My attack, majority comes from both of that IP.
mystvearn is offline   Reply With Quote
Old 04-24-2004, 12:32 PM   #17
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
Any PC Mech moderator can use the "IP: Logged" link in each post.

Port scanner "Attacks" from that IP range are one of 2 things - your ISP scanning your ports for security or functional reasons, or some other customer playing games with a port scanner. Just let the firewall do its job.
glc is offline   Reply With Quote
Old 04-24-2004, 12:38 PM   #18
Member (9 bit)
 
MulderMan's Avatar
 
Join Date: Dec 2003
Location: England
Posts: 362
Send a message via AIM to MulderMan
well my dad made me read the t+c of my isp when he got a email wrongly accusing me of sending virsues, and legaly i cant scan ports through my account. is this the same for all isps?

You must not use the Services to carry out Port scanning/probing (which is an attempt to identify an open gateway into another Internet user's machine). Where it has been identified that an account has been used for this activity ntl may withdraw the Services without notice.
MulderMan is offline   Reply With Quote
Old 04-25-2004, 12:36 AM   #19
Anime:Any-may
 
mystvearn's Avatar
 
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
I see. Thanks
mystvearn is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:31 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2