Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - TCP port attacks

 
Thread Tools Search this Thread
Old 11-09-2003, 05:13 PM   #1
Default TCP port attacks


Hi I wonder if anyone can help me with this.

I have noticed recently that someone is scanning my system on an
almost constant basis (every 5 secs or so). The accesses are being
blocked by my Kerio personal firewall and their report looks a little
like this (I have taken out the time and date to make it smaller):

Rule 'TCP ack packet attack': Blocked: In TCP, power
[127.0.0.1:80]->localhost:1945, Owner: no owner
Rule 'TCP ack packet attack': Blocked: In TCP, power
[127.0.0.1:80]->localhost:1945, Owner: no owner
Rule 'TCP ack packet attack': Blocked: In TCP, power
[127.0.0.1:80]->localhost:1983, Owner: no owner
Rule 'TCP ack packet attack': Blocked: In TCP,
66.220.17.151:80->localhost:1983, Owner: no owner
Rule 'TCP ack packet attack': Blocked: In TCP, power
[127.0.0.1:80]->localhost:1975, Owner: no owner

Now I believe the 127.0.0.1 should be a loop back from my own machine,
but there is nothing going out from my machine at all - it is just
receiving. So I figure that the scanner/attacker has somehow masked
their address. The port number is changing all the time. I have also
noticed that there are often accesses from 66.220.17.151:80 in between
the others and that typically this will be the same port as the
previous "loop back" one. I have checked out this address which is
something to do with the infamous www.lop.com, but I have little other
idea about what is happening and my ISP doesn't seem to want to know.
I have disconnected and reconnected several times (so getting
different IP addresses from my ISP) and the scans/attacks keep coming.

Can anyone help?

Mike


Mike Franklin
  Reply With Quote
Old 11-09-2003, 06:59 PM   #2
Chuck
 
Posts: n/a
Default Re: TCP port attacks
On 9 Nov 2003 09:13:36 -0800, (Mike
Franklin) wrote:

>Hi I wonder if anyone can help me with this.
>
>I have noticed recently that someone is scanning my system on an
>almost constant basis (every 5 secs or so). The accesses are being
>blocked by my Kerio personal firewall and their report looks a little
>like this (I have taken out the time and date to make it smaller):
>
>Rule 'TCP ack packet attack': Blocked: In TCP, power
>[127.0.0.1:80]->localhost:1945, Owner: no owner
>Rule 'TCP ack packet attack': Blocked: In TCP, power
>[127.0.0.1:80]->localhost:1945, Owner: no owner
>Rule 'TCP ack packet attack': Blocked: In TCP, power
>[127.0.0.1:80]->localhost:1983, Owner: no owner
>Rule 'TCP ack packet attack': Blocked: In TCP,
>66.220.17.151:80->localhost:1983, Owner: no owner
>Rule 'TCP ack packet attack': Blocked: In TCP, power
>[127.0.0.1:80]->localhost:1975, Owner: no owner
>
>Now I believe the 127.0.0.1 should be a loop back from my own machine,
>but there is nothing going out from my machine at all - it is just
>receiving. So I figure that the scanner/attacker has somehow masked
>their address. The port number is changing all the time. I have also
>noticed that there are often accesses from 66.220.17.151:80 in between
>the others and that typically this will be the same port as the
>previous "loop back" one. I have checked out this address which is
>something to do with the infamous www.lop.com, but I have little other
>idea about what is happening and my ISP doesn't seem to want to know.
>I have disconnected and reconnected several times (so getting
>different IP addresses from my ISP) and the scans/attacks keep coming.
>
>Can anyone help?
>
>Mike


Mike,

Since you're concerned, the logical thing would be to look for malware
- Lop for instance. Get / update Spybot S&D and HijackThis - both
free. Start with this article:
http://forums.spywareinfo.com/index.php?showtopic=5187

Do you have a router, or are you just protected by Kerio?

Cheers,


Chuck
I hate spam - PLEASE get rid of the spam before emailing me!
Paranoia comes from experience - and is not necessarily a bad thing.


Chuck
  Reply With Quote
Old 11-10-2003, 12:30 PM   #3
Robin T Cox
 
Posts: n/a
Default Re: TCP port attacks
(Mike Franklin) wrote in
news: om:

> Hi I wonder if anyone can help me with this.
>
> I have noticed recently that someone is scanning my system on an
> almost constant basis (every 5 secs or so). The accesses are being
> blocked by my Kerio personal firewall and their report looks a little
> like this (I have taken out the time and date to make it smaller):
>
> Rule 'TCP ack packet attack': Blocked: In TCP, power
> [127.0.0.1:80]->localhost:1945, Owner: no owner
> Rule 'TCP ack packet attack': Blocked: In TCP, power
> [127.0.0.1:80]->localhost:1945, Owner: no owner
> Rule 'TCP ack packet attack': Blocked: In TCP, power
> [127.0.0.1:80]->localhost:1983, Owner: no owner
> Rule 'TCP ack packet attack': Blocked: In TCP,
> 66.220.17.151:80->localhost:1983, Owner: no owner
> Rule 'TCP ack packet attack': Blocked: In TCP, power
> [127.0.0.1:80]->localhost:1975, Owner: no owner
>
> Now I believe the 127.0.0.1 should be a loop back from my own machine,
> but there is nothing going out from my machine at all - it is just
> receiving. So I figure that the scanner/attacker has somehow masked
> their address. The port number is changing all the time. I have also
> noticed that there are often accesses from 66.220.17.151:80 in between
> the others and that typically this will be the same port as the
> previous "loop back" one. I have checked out this address which is
> something to do with the infamous www.lop.com, but I have little other
> idea about what is happening and my ISP doesn't seem to want to know.
> I have disconnected and reconnected several times (so getting
> different IP addresses from my ISP) and the scans/attacks keep coming.
>
> Can anyone help?
>
> Mike
>


In Kerio, logging suspicious packets in Advanced > Miscellaneous view will
generate the "ack" packets logs.

See:
http://www.dslreports.com/forum/rema...erio~mode=flat



Robin T Cox
  Reply With Quote
Old 11-11-2003, 06:52 PM   #4
Mike Franklin
 
Posts: n/a
Default Re: TCP port attacks
Hi Chuck,

Thanks for you response

> Since you're concerned, the logical thing would be to look for malware
> - Lop for instance. Get / update Spybot S&D and HijackThis - both
> free. Start with this article:
> http://forums.spywareinfo.com/index.php?showtopic=5187


I'll have to have a look at that - just got to find the time!

> Do you have a router, or are you just protected by Kerio?


don't have a router - just a simple dial up connection with Kerio
running. I live in the remote highlands of Scotland and it's going to
be a while before I get any kind of broadband connection to make me
even think about a more sophisticated set up!

The annoying thing is that the continuous tickle to my connection
stops my system from doing an idle timeout and hanging up the line.

Cheers Mike


Mike Franklin
  Reply With Quote
Old 11-11-2003, 06:54 PM   #5
Mike Franklin
 
Posts: n/a
Default Re: TCP port attacks
Robin T Cox <> wrote in message
> In Kerio, logging suspicious packets in Advanced > Miscellaneous view will
> generate the "ack" packets logs.


Yup that's how I got the report. Set it to log suspicious packets as I
was trying to see who or what was continously scanning me. I am just
wondering what these could be and if there is anyway of stopping them
doing it.

Mike


Mike Franklin
  Reply With Quote
Old 11-12-2003, 12:28 AM   #6
Chuck
 
Posts: n/a
Default Re: TCP port attacks
On 11 Nov 2003 10:52:06 -0800, (Mike
Franklin) wrote:

>Hi Chuck,
>
>Thanks for you response
>
>> Since you're concerned, the logical thing would be to look for malware
>> - Lop for instance. Get / update Spybot S&D and HijackThis - both
>> free. Start with this article:
>> http://forums.spywareinfo.com/index.php?showtopic=5187

>
>I'll have to have a look at that - just got to find the time!
>
>> Do you have a router, or are you just protected by Kerio?

>
>don't have a router - just a simple dial up connection with Kerio
>running. I live in the remote highlands of Scotland and it's going to
>be a while before I get any kind of broadband connection to make me
>even think about a more sophisticated set up!
>
>The annoying thing is that the continuous tickle to my connection
>stops my system from doing an idle timeout and hanging up the line.
>
>Cheers Mike


Mike,

I'm not sure, but I'd suspect a router blocking the constant tickle
might be more responsive to your wanting to hang up the line when
you're idle.

Routers that support PPP dialup are available - they're not as cheap
as broadband routers (my SMC PPP router cost $80 for the equivalent of
a $50 broadband only Linksys). They do take the load off the cpu by
blocking the crappy traffic AND by letting me remove DUN (RAS). Come
to think of it, RAS was a considerable drain on the cpu by itself (I
last used RAS on a PII 450).

The biggest benefit of the router, for me, was removing the proxy
server (that you don't need with just 1 computer). But the two weeks
I spent early this year, on dialup, waiting for my DSL to be
transferred to my current ISP, was not nearly as traumatic for me with
my SMC to manage my dialup connection than it would have been with RAS
and a proxy server. My dialup connection was waaay more stable with
the router than I ever remember it under RAS.

Unfortunately, all dialup services are NOT PPP compatible. My mother
is on MSN - it requires their custom client software - I spent a week
there this year (and wasted about $200) trying to get an SMC dialup
router to work on her MSN. (

Cheers,

Chuck
I hate spam - PLEASE get rid of the spam before emailing me!
Paranoia comes from experience - and is not necessarily a bad thing.


Chuck
  Reply With Quote
Old 11-12-2003, 03:52 PM   #7
Robin T Cox
 
Posts: n/a
Default Re: TCP port attacks
(Mike Franklin) wrote in
news: om:

> Robin T Cox <> wrote in message
>> In Kerio, logging suspicious packets in Advanced > Miscellaneous view
>> will generate the "ack" packets logs.

>
> Yup that's how I got the report. Set it to log suspicious packets as I
> was trying to see who or what was continously scanning me. I am just
> wondering what these could be and if there is anyway of stopping them
> doing it.
>
> Mike


I think the suggestion in the link I quoted is that the Kerio setting
itself simply generates a lot of false positives, and so nobody is actually
scanning you.


Robin T Cox
  Reply With Quote
Old 11-13-2003, 12:58 PM   #8
Mike Franklin
 
Posts: n/a
Default Re: TCP port attacks
Chuck <> wrote in message >
> Mike,
>
> I'm not sure, but I'd suspect a router blocking the constant tickle
> might be more responsive to your wanting to hang up the line when
> you're idle.
>
> Routers that support PPP dialup are available - they're not as cheap
> as broadband routers (my SMC PPP router cost $80 for the equivalent of
> a $50 broadband only Linksys). They do take the load off the cpu by
> blocking the crappy traffic AND by letting me remove DUN (RAS). Come
> to think of it, RAS was a considerable drain on the cpu by itself (I
> last used RAS on a PII 450).
>
> The biggest benefit of the router, for me, was removing the proxy
> server (that you don't need with just 1 computer). But the two weeks
> I spent early this year, on dialup, waiting for my DSL to be
> transferred to my current ISP, was not nearly as traumatic for me with
> my SMC to manage my dialup connection than it would have been with RAS
> and a proxy server. My dialup connection was waaay more stable with
> the router than I ever remember it under RAS.
>
> Unfortunately, all dialup services are NOT PPP compatible. My mother
> is on MSN - it requires their custom client software - I spent a week
> there this year (and wasted about $200) trying to get an SMC dialup
> router to work on her MSN. (
>
> Cheers,
>
> Chuck


Thanks for that Chuck very interesting I'll have to investigate a
router - I confess I'm not very knowledgable about networks and stuff
and had always thought such things were for much larger setups.

Mike


Mike Franklin
  Reply With Quote
Old 11-13-2003, 01:00 PM   #9
Mike Franklin
 
Posts: n/a
Default Re: TCP port attacks
> I think the suggestion in the link I quoted is that the Kerio setting
> itself simply generates a lot of false positives, and so nobody is actually
> scanning you.


My profound apologies - I missed the link altogether in your post
(doh) and have now had a look at it and it does seem very interesting.
I have now applied most of the ideas discussed in that thread and it
now looks more like the traffic on my connection is primarily echo
requests from my own isp

Mike


Mike Franklin
  Reply With Quote
Old 11-14-2003, 10:18 AM   #10
Robin T Cox
 
Posts: n/a
Default Re: TCP port attacks
(Mike Franklin) wrote in
news: om:

>> I think the suggestion in the link I quoted is that the Kerio setting
>> itself simply generates a lot of false positives, and so nobody is
>> actually scanning you.

>
> My profound apologies - I missed the link altogether in your post
> (doh) and have now had a look at it and it does seem very interesting.
> I have now applied most of the ideas discussed in that thread and it
> now looks more like the traffic on my connection is primarily echo
> requests from my own isp
>
> Mike
>


No problem - I must confess that when I first came across this it seemed
very odd!

Robin


Robin T Cox
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can not access console port of Cisco 7200 vxr mansurbd Hardware 1 01-12-2009 06:53 PM
How to check current event and port status for Aliwei FXO gateway Robin wang Hardware 0 04-11-2008 09:54 AM
Port 445: Effective/Safe Blocking Samwise General Help Related Topics 0 01-06-2008 09:19 PM
Long, regarding a "lost" COM port smackedass A+ Certification 4 02-05-2007 04:55 PM
non plug and play device on com port? David K A+ Certification 1 07-18-2003 08:38 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46