Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Someone is checking my public I.P. Addresses!

Status
Not open for further replies.

jcfrasco

IS-IT--Management
Apr 27, 2001
89
US
I checked my firewall logs the other day and I found a list of unknown I.P. addresses ,reverse I.P. lookup shows there from .cz, that were running down my list of public I.P. addresses. My log said they were using udp services and fortunatly they were denied. What services use udp and even though they were denied is there any information about my network they could have picked up from their scans. Also, I'm interested in knowing, not because I want to try it but because I want to protect myself from it, what programs hackers use to try to get into a system. I purchased a Watchguard Firewall for my system but I hate that feeling that something is left wide open. After all, a firewall is only as good as the people that are setting it up and monitoring it and I'm still reading the manual.

I appreciate any suggestions or advice anyone has to offer.

Sincerely,
jcfrasco
 
If your firewall denied the access you need not worry about anything. More trouble will come up if the firewall does not report anything about an access to your station

;)

hnd
hasso55@yahoo.com

 
A lot of different services can use UDP. Watchguards auto-block port scans (once they detect it as such) so automated brute-force scans (which is probably what you saw) don't give prospective attackers much information.
-Steve
 
You may want to pick a copy of Hacking Exposed. It is a good resource for understanding how hackers operate so that you can defend yourself from them. I am working my way through an old edition, but plan on picking up the new edition soon. It was quite an eye opener. Fortunately, I am very security minded and had already fixed many of the holes, but there were some that I was unaware of.
 
jcfrasco -
Someone was running a port scanner on your subnet. Happens all the time. I consider it an unfriendly act, and I try & send an email to their ISP's abuse address. Nothing ever comes of it, I'm sure, but I like to discourage the practice.

Chip H.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top