Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Strange - my router "reacts" to intrusion attempts

 
Thread Tools Search this Thread
Old 03-11-2005, 03:48 PM   #1
Default Strange - my router "reacts" to intrusion attempts


We have a NAT router with SPI protecting our small LAN.

When I go to http://grc.com and run the shields up scan on common ports, it
shows the following ports as open; 21, 23 and 80. If I run the scan again a
few seconds later all ports show as stealthed. If I leave it for a few
minutes and run the scan again the ports are open again.

OK so the firewall is "reacting" to an intrusion attempt, but wouldn't it be
better to be closed or stealthed the FIRST time an intrusion was attempted?
Can anyone comment on this routers behaviour? I have never seen a router do
this before, is it a potential risk, or is it being very "smart"?

Thanks

Paul




Paul H
  Reply With Quote
Old 03-11-2005, 03:54 PM   #2
David H. Lipman
 
Posts: n/a
Default Re: Strange - my router "reacts" to intrusion attempts
From: "Paul H" <>

| We have a NAT router with SPI protecting our small LAN.
|
| When I go to http://grc.com and run the shields up scan on common ports, it
| shows the following ports as open; 21, 23 and 80. If I run the scan again a
| few seconds later all ports show as stealthed. If I leave it for a few
| minutes and run the scan again the ports are open again.
|
| OK so the firewall is "reacting" to an intrusion attempt, but wouldn't it be
| better to be closed or stealthed the FIRST time an intrusion was attempted?
| Can anyone comment on this routers behaviour? I have never seen a router do
| this before, is it a potential risk, or is it being very "smart"?
|
| Thanks
|
| Paul
|

I wonder if Stateful Packet Inspection has something to do with that... ?


--
Dave




David H. Lipman
  Reply With Quote
Old 03-11-2005, 04:27 PM   #3
Martin
 
Posts: n/a
Default Re: Strange - my router "reacts" to intrusion attempts
Paul H wrote:
> We have a NAT router with SPI protecting our small LAN.
>
> When I go to http://grc.com and run the shields up scan on common ports, it
> shows the following ports as open; 21, 23 and 80. If I run the scan again a
> few seconds later all ports show as stealthed. If I leave it for a few
> minutes and run the scan again the ports are open again.
>
> OK so the firewall is "reacting" to an intrusion attempt, but wouldn't it be
> better to be closed or stealthed the FIRST time an intrusion was attempted?


yes, you'll need to configure it correctly, I hate to say it, RTFM
(there, that's a first for me) Probably open for remote management
unless you have set up port forwarding rules to real servers. You really
should close off the remote management features, or set the router so it
only accepts them from specific IP addresses or through the VPN

> Can anyone comment on this routers behaviour? I have never seen a router do
> this before, is it a potential risk, or is it being very "smart"?


It's being 'smart', lots of firewalls do this if they think they are
being port scanned. They drop all traffic from the IP address that is
doing the scanning

>
> Thanks
>
> Paul
>
>



Martin
  Reply With Quote
Old 03-15-2005, 04:19 AM   #4
winged
 
Posts: n/a
Default Re: Strange - my router "reacts" to intrusion attempts
Paul H wrote:
> We have a NAT router with SPI protecting our small LAN.
>
> When I go to http://grc.com and run the shields up scan on common ports, it
> shows the following ports as open; 21, 23 and 80. If I run the scan again a
> few seconds later all ports show as stealthed. If I leave it for a few
> minutes and run the scan again the ports are open again.
>
> OK so the firewall is "reacting" to an intrusion attempt, but wouldn't it be
> better to be closed or stealthed the FIRST time an intrusion was attempted?
> Can anyone comment on this routers behaviour? I have never seen a router do
> this before, is it a potential risk, or is it being very "smart"?
>
> Thanks
>
> Paul
>
>

It "may" be your ISP firewall interfering as well. I have seen this
occur. Some firewall do block for a set time period, after a threshold
has been met, though the behavior would not be expected in a Nat router.
I suspect your ISP has a firewall that is set to watch for external
scans and blocks the scanner for a few minutes until the activity stops.

Winged


winged
  Reply With Quote
Old 03-16-2005, 02:39 PM   #5
Paul H
 
Posts: n/a
Default Re: Strange - my router "reacts" to intrusion attempts

"winged" <> wrote in message
news:d15no7$...
> Paul H wrote:
>> We have a NAT router with SPI protecting our small LAN.
>>
>> When I go to http://grc.com and run the shields up scan on common ports,
>> it shows the following ports as open; 21, 23 and 80. If I run the scan
>> again a few seconds later all ports show as stealthed. If I leave it for
>> a few minutes and run the scan again the ports are open again.
>>
>> OK so the firewall is "reacting" to an intrusion attempt, but wouldn't it
>> be better to be closed or stealthed the FIRST time an intrusion was
>> attempted? Can anyone comment on this routers behaviour? I have never
>> seen a router do this before, is it a potential risk, or is it being very
>> "smart"?
>>
>> Thanks
>>
>> Paul

> It "may" be your ISP firewall interfering as well. I have seen this
> occur. Some firewall do block for a set time period, after a threshold
> has been met, though the behavior would not be expected in a Nat router. I
> suspect your ISP has a firewall that is set to watch for external scans
> and blocks the scanner for a few minutes until the activity stops.


Thanks for the idea, but after further testing that doesn't seem to be
what's happening..

I have also run a sygate quick scan
(http://scan.sygatetech.com/prequickscan.html) and the same ports were
reported as open. I repeated the scan several times and got the same results
each time. I also tried the scan at hackerwatch.com and found the same ports
were also reported as open.

What is going on here? To summarise:

1st scan using grc.com's Shieldsup reports ports 21,23 and 80 are open
2nd scan using grc.com's Shieldsup reports all ports stealthed
Several scans at sygatetech and hackerwatch consistently report these three
ports are open.

Are they open? If they are then it would seem that ShieldsUp is a very
dangerous and misleading tool.

What do you think?

Paul






Paul H
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
router to router edwardsmichael Hardware 5 10-31-2009 10:51 PM
Problem Connecting Through Router Nobody404 General Help Related Topics 0 07-10-2007 11:28 PM
Adsl Router > Dual Wan Load Balancing Router > 24 port Switch Hub nazeth Hardware 0 03-28-2007 09:36 AM
Connecting dsl modem, switch and WiFi router RameshMeda Hardware 0 11-03-2006 01:58 PM
wireless router vs Acess point Gary A+ Certification 4 12-01-2005 03:55 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46