My network colleagues tell me that my Win2k server is port scanning the network. Now I checked for viruses and tried to stop any unnecessary processes from running. How can I tell what's causing the port scanning? The server is up to date with patches.
If this is an HP server, did you install the Insight Manager application? It will perform SNMP sweeps of the network.
PSC
Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
You may want to check for the Nachi (McAfee)/Welchia (Symantec) worm. It does a ping sweep, then a port scan when it finds a live host. If you have this worm you will also see high CPU utilization on your routers with no corresponding interface utilization.
It's also possible that there is a device which is spoofing the source address. Check your snort logs for the MAC address of the sending host and make sure that it matches your Dell box.
PSC
Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
This server is virus free according to McAfee's NetShield but I will do a re-check. Thank you also for the snort log suggestion. I am already expecting a copy of the logs.
I do tend to notice a lot of packets being sent and received by the server but I attributed that to AD related communications between the server and the 180 machines in the domain. I tried scanning with EtherPeek but I saw nothing that alarmed me.
Also, make sure that your IDS guy isn't confusing a TCP SYN flood with a port scan. I've seen windows boxes excite firewalls and IDS's with half open TCP connections.
PSC
Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
You could also download Ethereal and do some packet capturing to see what is going happening on you network. I use ethereal often to make sure my network doesnt have anything unusual going around. You can use ethereal to listen just to your suspect server's IP address to help narrow things down.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.