Portscan Attempt Blocked

Sum1

Lifetimer
Joined
Oct 25, 2006
Messages
2,013
Reaction score
8
Points
38
Hey all,

My antivirus shows me when it blocks port scans. Lately I've been seeing it a little more often (or maybe just noticing it, I'm not sure) coming up as telling me it blocked a port scan from a 125. whatever IP. Should I be concerned about this?
 
Hey all,

My antivirus shows me when it blocks port scans. Lately I've been seeing it a little more often (or maybe just noticing it, I'm not sure) coming up as telling me it blocked a port scan from a 125. whatever IP. Should I be concerned about this?
I wouldn't, as long as your system is reasonably secure (firewall, and behind a NAT router).

People do this all the time - and I mean ALL the time. Should see the logs on mmobugs.com. Some people have nothing productive to do with their life.

htw
 
So does someone have to specifically target me and my box to do these scans, or are they blanket over a wide area and I'm just getting caught up in it?

Guess I'm curious if I'm being targeted or if Im just getting caught in the wave.
 
For most people, they just target ranges of IPs, looking for servers (with regards to the services, not the hardware). Then they usually get all script kiddie & try to hammer in to what you have, e.g., ssh, telnet, ftp - looking for drop space for warez, or whatever the hell it is they are bored with & want to waste their life on.

You *could* be picked by someone, if they're one of those people, & get your IP. Or some unscrupulous web site fucker is doing it. However, I doubt it. Like I said, it's very very common.

htw
 
It may be someone with a ipad or iPhone using the inet app. It gives you all ips I'n range and the option to do scan open ports.
 
lol yeah. It's unreal how many request I get for someone trying to login as administrator into my ftp server. The one reason I don't use a login name that =P
 
There are tons of automated worms out there that try to blindly hack before moving on to the next IP.

I was bored a week or two ago and wrote a fake telnet server to log such attacks and see what they are actually doing (Kinda like a honeypot).