Networks Port Scan detected

Discussion in 'Tech Support' started by sparkyboy22, 16 Jan 2012.

  1. sparkyboy22

    sparkyboy22 Web Tinkerer

    Joined:
    3 May 2010
    Posts:
    738
    Likes Received:
    35
    A fair old time ago I set my router up to allow incoming remote desktop connections and send them to my PC.

    At the time there was an option about sending a mail if dodgy activity was detected. (words to that effect anyway.)

    I had clean forgotten about it until I just got an email.

    Subject: NETGEAR *Security Alert* [41:DA:A5]
    Contents: TCP Packet - Source:88.103.182.246 Destination:2.120.246.69 - [PORT SCAN]

    Should I be worried and should I be doing anything to increase security?
     
  2. Kernel

    Kernel Likes cheese

    Joined:
    29 Sep 2003
    Posts:
    1,182
    Likes Received:
    37
    Shows it originated from the Czech Republic.
    [​IMG]
     
    sparkyboy22 likes this.
  3. Margo Baggins

    Margo Baggins I'm good at Soldering Super Moderator

    Joined:
    28 May 2010
    Posts:
    5,650
    Likes Received:
    268
    how often do you use remote desktop? If you are worried, just close the port for a couple of weeks.
     
  4. sparkyboy22

    sparkyboy22 Web Tinkerer

    Joined:
    3 May 2010
    Posts:
    738
    Likes Received:
    35
    Not anymore. Using Home Prem now so doesnt support it.

    Not even sure if the port is still open!

    So nothing really to worry about then. Just close the port if its still open and forget it?
     
  5. Margo Baggins

    Margo Baggins I'm good at Soldering Super Moderator

    Joined:
    28 May 2010
    Posts:
    5,650
    Likes Received:
    268
    yeah close port - if its not open, no ones coming in :)
     
    sparkyboy22 likes this.
  6. faugusztin

    faugusztin I *am* the guy with two left hands

    Joined:
    11 Aug 2008
    Posts:
    6,946
    Likes Received:
    269
    LOL, if you really got scanned just once in all that time, then call yourself lucky, in standard scenario your public IP get port scanned every few minutes.
     
    sparkyboy22 likes this.
  7. towelie

    towelie How do I Internet!!

    Joined:
    1 Sep 2011
    Posts:
    399
    Likes Received:
    10
    Faugusztin is correct i seen hundred of time when watching a live firewall port scans and even DOS's not much you can do.That why people lock down as many ports as possible leave only what has to be open open.

    Close the port and you will be ok.May be worth keeping your router firmwares up to date
     
    sparkyboy22 likes this.
  8. Scorpuk

    Scorpuk Minimodder

    Joined:
    10 Jan 2012
    Posts:
    724
    Likes Received:
    9
    Last few lines from my servers authentication log filtered to fails:

    Code:
    Dec 20 09:14:16 Server sshd[4910]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 09:19:18 Server sshd[2704]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 09:35:37 Server sshd[3274]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 11:58:01 Server sshd[8518]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 12:23:22 Server sshd[9312]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 15:19:04 Server sshd[13546]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 20 15:20:44 Server sshd[13693]: reverse mapping checking getaddrinfo for 46-37-178-47.static.hostnoc.net [46.37.178.47] failed - POSSIBLE BREAK-IN ATTEMPT!
    Dec 21 14:18:27 Server sshd[13262]: reverse mapping checking getaddrinfo for 46-37-189-62.static.hostnoc.net [46.37.189.62] failed - POSSIBLE BREAK-IN ATTEMPT!
    Jan  6 15:58:45 Server sshd[30353]: reverse mapping checking getaddrinfo for 89.104.226.43.reverse.converged.co.uk [89.104.226.43] failed - POSSIBLE BREAK-IN ATTEMPT!
    Jan 15 13:24:23 Server sshd[7768]: reverse mapping checking getaddrinfo for 89.104.226.43.reverse.converged.co.uk [89.104.226.43] failed - POSSIBLE BREAK-IN ATTEMPT!
    Jan 17 09:31:21 Server sshd[23584]: reverse mapping checking getaddrinfo for 89.104.226.43.reverse.converged.co.uk [89.104.226.43] failed - POSSIBLE BREAK-IN ATTEMPT!
    Jan 17 09:39:01 Server sshd[24138]: reverse mapping checking getaddrinfo for 89.104.226.43.reverse.converged.co.uk [89.104.226.43] failed - POSSIBLE BREAK-IN ATTEMPT!
    Stay away from standard port numbers and you should be a little more secure. :thumb:
     
    Last edited: 17 Jan 2012
    sparkyboy22 likes this.
  9. sparkyboy22

    sparkyboy22 Web Tinkerer

    Joined:
    3 May 2010
    Posts:
    738
    Likes Received:
    35
    Thanks all, really appreciated.
     

Share This Page