Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-30-2005, 12:44 PM
Ron
Guest
 
Posts: n/a
Default Someone's Busy Scanning

My firewall is telling me that someone is scanning my UDP ports 1028,
1030, 1031, 1032, and 4297. Can anyone tell me what's so significant
about those ports, and what would happen if they were left unprotected?

Thanks.

Ron


Reply With Quote
  #2 (permalink)  
Old 10-30-2005, 02:23 PM
Bit Twister
Guest
 
Posts: n/a
Default Re: Someone's Busy Scanning

On 30 Oct 2005 04:44:12 -0800, Ron wrote:
> My firewall is telling me that someone is scanning my UDP ports 1028,
> 1030, 1031, 1032, and 4297. Can anyone tell me what's so significant
> about those ports,


http://www.dshield.org//port_report.php?port=
http://isc.sans.org/port_details.php?port=
http://lists.thedatalist.com/portlist/lookup.php?port=

> and what would happen if they were left unprotected?


Leaving any inbound attempt port unprotected is asking for any type of
trouble and can change anytime the malware author/script kiddie wants
to change the payload.

Reply With Quote
  #3 (permalink)  
Old 10-30-2005, 02:36 PM
Anders
Guest
 
Posts: n/a
Default Re: Someone's Busy Scanning

Ron wrote:
> My firewall is telling me that someone is scanning my UDP ports 1028,
> 1030, 1031, 1032, and 4297. Can anyone tell me what's so significant
> about those ports, and what would happen if they were left unprotected?
>
> Thanks.
>
> Ron
>

http://www.iana.org/assignments/port-numbers is a good place if you want
to see what certain ports are for, but they can be used for almost any
thing,
and that would answer you second qestion too.

If you donīt now what it is block it, and if you now what it is,
block it any way...well mostley.

Anders

Reply With Quote
  #4 (permalink)  
Old 10-30-2005, 06:30 PM
Moe Trin
Guest
 
Posts: n/a
Default Re: Someone's Busy Scanning

In the Usenet newsgroup alt.computer.security, in article
<1130676252.667561.176090@g14g2000cwa.googlegroups .com>, Ron wrote:

>My firewall is telling me that someone is scanning my UDP ports 1028,
>1030, 1031, 1032, and 4297.


Sounds like a "personal firewall" trying to impress you with useless
noise. The 102x/103x crap is typically spammers trying to send pop-up
advertisements (windoze Messenger service). They are not scanning, or
trying to connect or indeed do anything harmful other than getting you
to come to their website and use your credit card to buy some useless
crap. As for 4297 - who knows - it's a userland port that could be
just about anything.

Port numbers are not cast in stone. Certain services use what are known
as "well known ports" by default - so that users can find them. But
just because the well known port for DNS is 53, this does not prevent
someone from using port 53 on their computer for ANY service of any kind.
The Internet Police will not come and arrest him for doing so.

>Can anyone tell me what's so significant about those ports,


They are opportunities for spammers to find stupid customers

>and what would happen if they were left unprotected?


You'd see something that looks like

SYSTEM
ALERT
Windows has encountered an Internal Error
Your windows registry is corrupted.
We recommend a complete system scan.

Visit
http://some.wankers.website
To repair now!

that's the contents of a message seen on a packet sniffer I was using to
investigate a bandwidth problem. It's false for several reasons, first
and most obviously because it suggests going to some website nobody had
ever heard of (doing a whois search revealed the domain had been registered
only 23 hours earlier), and second because the sniffer doesn't run windoze.

There are few services using UDP that are needed. DNS queries (used to
translate hostnames to IP addresses and vice-versa) normally run on UDP
(random port on your side, 53 on the server), and that's about it. A
wide open windoze box is spewing from/to 137-139, and should be taken
off line until the user can figure out how to turn that crap off, but
that's pretty much it.

Old guy

Reply With Quote
  #5 (permalink)  
Old 10-31-2005, 10:15 AM
Ron
Guest
 
Posts: n/a
Default Re: Someone's Busy Scanning

Thanks, for the information guys; it is much appreciated and it's nice
to know
my firewall is doing it's job. :-)

Ron


Reply With Quote
  #6 (permalink)  
Old 11-01-2005, 08:06 PM
Moe Trin
Guest
 
Posts: n/a
Default Re: Someone's Busy Scanning

In the Usenet newsgroup alt.computer.security, in article
<kladm1des9nkflmr6pl63h092pl1417and@4ax.com>, Jim Watt wrote:

>"Ron" <ryon@quik.com> wrote:


>> it's nice to know my firewall is doing it's job. :-)


>Actually is itsn't its getting you worried about a threat that is not
>there;


I think it was originally posted in 'comp.security.firewalls', but

Their main use is telling the ones who use it that some host in Korea or
Kenya attempted to connect to a trojan that they don't have installed.

>unless those ports are open, ie being listened to by a rogue process on
>your computer, the fact that someone is scanning them is pretty much
>immaterial.


Bottom line - did your firewall block this crap? If yes, then end of story.
If no, then disconnect the computer until it can be configured properly, or
return it to the store as being to complicated for you.

Knowing that some host "attacked" you by attempting to connect to an
unopened port is useless. What are you going to do, call the Internet
Police? Do you have the National Missile Launch Codes and are not
afraid to use them?

>What you really need to know is what is or is not running on your
>machine.


What he said!

Old guy

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
AVC-3610 dual tuner... always busy??? Noozer alt.comp.hardware 0 03-15-2007 03:48 PM
Application Impacts of Real-Time anti virus scanning and guidance for its use within an intranet AppDev alt.computer.security 0 02-05-2007 03:58 PM
UK Busy tone on an SPA-3000? Ian Pawson uk.telecom.voip 5 12-22-2006 10:07 AM
Re: Port scanning Shannon alt.comp.hardware 0 10-17-2006 07:23 AM
Harris-STAT scanning software - help? Michael Horowitz comp.security.misc 0 08-30-2006 10:14 AM


All times are GMT. The time now is 07:49 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45