|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
My firewall registered an attack from an IP before I connect to the internet & I have not even begun connecting. What does this mean?
Using sygate personal firewall.
__________________
CPU: Intel E-5200. Graphics: Saphire Radeon 4770 HD 512 MB. Motherboard: Gigabyte GA-EP43-DS3L. Memory: Corsair XMS2 Xtreme Performance 4 GB ( 2 x 2 GB ), Chasis: Antec Three Hundred. PSU: Corsair CX400W. Optical Drive: Sony Optiarc SATA DVD +-RW. Storage: Seagate Barracuda 7200.12 500GB SATA. Peripherals: Dell E1905EP 19" UltraSharp LCD; LG M227WD (Dual screen), HP 4180 Printer, Canon S400SP Printer & Lide20 Scanner; Philiphs HP 890, Edifier MP230. OS: Win 7 (64 bit). Laptop: Toshiba Satellite M50 |
|
|
|
|
|
#2 |
|
Member (11 bit)
|
Are you on a lan? It might just be picking up lan trafic.
|
|
|
|
|
|
#3 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
What you see as an attack is very often legitimate traffic, you have to analyze what it's telling you, not just assume someone is hammering you.
I have alerts turned off in ZA, and hardly ever look at the log - I just let the firewall do its job. If an app wants access and it's not already preapproved by me, it will still ask. Last edited by glc; 04-22-2004 at 04:45 PM. |
|
|
|
|
|
#4 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
No. I ahve broadband-DSL. Before I went offline, I see the same P attacking. & just as I wanted to enter the internet after restart, the same IP attacking me agan.
|
|
|
|
|
|
#5 | |
|
Member (11 bit)
|
Quote:
|
|
|
|
|
|
|
#6 |
|
Member (9 bit)
|
Lol yeh, let us have some fun with this IP...
|
|
|
|
|
|
#7 | |
|
Member (11 bit)
|
Quote:
Last edited by Blue_Gundam2002; 04-23-2004 at 12:26 AM. |
|
|
|
|
|
|
#8 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
Teen - we don't behave like that around here.
- Moderator - |
|
|
|
|
|
#9 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
The IP is 219.93.197.62. I think nearly 100 attacks from it.
my DSL using dynamic IP. Sygate says its security type is port scan. Severity:minor Direction: incoming Maybe its my IP? |
|
|
|
|
|
#10 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
Well, I just looked up your IP when you made this post - and it's close enough to make me conclude it's coming from your ISP. They are probably just scanning their customers' ports for unauthorized servers and security issues that would affect their whole network. Either that, or it's another customer running a port scanner.
|
|
|
|
|
|
#11 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
Thanks. How did you find that out? I have lots of attacks, coming from 219.93.19(6/7).xxx alot. Maybe its normal. Thanks.
|
|
|
|
|
|
#12 |
|
Member (9 bit)
|
i looked it up and appears to be coming from malaysia so i presume its your isp. i use this to look up ips http://ip-to-country.webhosting.info/node/view/36
|
|
|
|
|
|
#13 |
|
Member (9 bit)
|
Very sorry, it was intended as a joke.
|
|
|
|
|
|
#14 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
Thanks,
|
|
|
|
|
|
#15 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
As a moderator, I can look up the IP address of every post. Your IP is 219.93.196.xxx, your ISP is very likely using the 219.93.196.xxx and 219.93.197.xxx subnets.
|
|
|
|
|
|
#16 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
I see. All forum mods have this ability? Even from different forums?
My attack, majority comes from both of that IP. |
|
|
|
|
|
#17 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
Any PC Mech moderator can use the "IP: Logged" link in each post.
Port scanner "Attacks" from that IP range are one of 2 things - your ISP scanning your ports for security or functional reasons, or some other customer playing games with a port scanner. Just let the firewall do its job. |
|
|
|
|
|
#18 |
|
Member (9 bit)
|
well my dad made me read the t+c of my isp when he got a email wrongly accusing me of sending virsues, and legaly i cant scan ports through my account. is this the same for all isps?
You must not use the Services to carry out Port scanning/probing (which is an attempt to identify an open gateway into another Internet user's machine). Where it has been identified that an account has been used for this activity ntl may withdraw the Services without notice. |
|
|
|
|
|
#19 |
|
Anime:Any-may
Join Date: Sep 2002
Location: Kota Bharu, Malaysia
Posts: 2,447
|
I see. Thanks
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|