PORTSCANS

Post non-phpwcms related topics here - but I don't want to see "hey check this or that other cms". Post if you have a point or worthwhile comment, don't post just to increase you post count!
Post Reply
Jan212
Posts: 859
Joined: Wed 28. Jan 2004, 21:38
Location: Solingen
Contact:

PORTSCANS

Post by Jan212 »

Does anybody else noticed or notice PORTSCANS on TCP ports:
2745, 135, 1025, 445 and 3127 ???
i have them till 50times a day from different ip's in my neighbourhood...
Regards/ Grüsse/ Groetjes - JAN212
------------------------------------------------
null212 - Büro für Kommunikation und Design
------------------------------------------------
Lyrikfetzen des Tages
1. Ist der Quelltext auch valide fragt Herr Müller ganz perfide.
2. Wat is dat een lekker ding.
3. Wer Vision hat soll zum Arzt gehen.
------------------------------------------------
brans

Post by brans »

it's possible that they are coming from the new Virus released on May 1. ?
Jan212
Posts: 859
Joined: Wed 28. Jan 2004, 21:38
Location: Solingen
Contact:

Post by Jan212 »

don't think so but i've noticed exploits on the lsass.exe and ipnat.sys, and the scans begann before- but it#s mysterious that they are only coming from neighbourhood ips
Regards/ Grüsse/ Groetjes - JAN212
------------------------------------------------
null212 - Büro für Kommunikation und Design
------------------------------------------------
Lyrikfetzen des Tages
1. Ist der Quelltext auch valide fragt Herr Müller ganz perfide.
2. Wat is dat een lekker ding.
3. Wer Vision hat soll zum Arzt gehen.
------------------------------------------------
User avatar
pSouper
Posts: 1552
Joined: Tue 11. Nov 2003, 15:45
Location: London
Contact:

Post by pSouper »

here's a port list and why they may be scanned..
http://lists.gpick.com/portlist/portlist.htm
a noticable clue is 135: W32.Blaster.Worm, W32/Lovsan.worm

and this is interesting...
http://www.parkerpc.com/reference/trojanports.html

i hope you run a nice firewall ;)
you will not be able to stop the 'incomming' just protect your self well my friend
User avatar
Paradroid
Posts: 176
Joined: Fri 19. Mar 2004, 13:14
Location: Wuppertal
Contact:

Post by Paradroid »

Hi Jan,

as pSouper said, these are "classical" trojan ports. There seems to be a freshly infected computer or network in your neighborhood ....

i'll take a look at my firewalls activity

cu

Achim
ParaDroid

knquadrat edv + marketing
http://www.knquadrat.de

phpWCMS Dokumentation | Deutsch | English
Jan212
Posts: 859
Joined: Wed 28. Jan 2004, 21:38
Location: Solingen
Contact:

Post by Jan212 »

my firewall is active all the time, but the system i work on is complete new... but xp alone is a damn security whole ;-) - i am using the bat! as e-mail client and avast antivirus... as desktop fw i have sygate pro
Regards/ Grüsse/ Groetjes - JAN212
------------------------------------------------
null212 - Büro für Kommunikation und Design
------------------------------------------------
Lyrikfetzen des Tages
1. Ist der Quelltext auch valide fragt Herr Müller ganz perfide.
2. Wat is dat een lekker ding.
3. Wer Vision hat soll zum Arzt gehen.
------------------------------------------------
Post Reply