Results 1 to 5 of 5

Thread: Floods of attempts to access ports

  1. #1
    Junior Member
    Join Date
    Sep 2002
    Posts
    3

    Floods of attempts to access ports

    Over the past week or so, my home network has had an increase of attempted access on different ports. The source IP has been different each time, but stuck to 3 TCP/IP ports. The destination address was different each time, but the port was the same. Anyone have any ideas on what could be causing this. All the attempts were stoped by Norton Internet Security. My home network is setup like the following:

    1 Windows 2000 Server, Configured as Domain Controler, DHCP, DNS
    4 desktop & 2 laptops, all running Windows XP Pro. Desktops are on a wired network and the laptops are connected through a Linksys 802.11b Access point with 64 bit WEP enabled
    1 Netgear Security router, connected to a switch on the internal side and a cable modem on the WAN side

    All computers have Norton Internet Security running, with the most recent updates installed. Windows on all machines are up to date, including recommended updates and drivers.

    The ports that were used follows:

    Source -> Destination
    2454 -> 11085
    4556 -> 11085
    2140 -> 11085

    Like I said above, both the source and destination IP's were different each time.

    If you need more information, let me know. Thanks.

  2. #2
    Senior Member IKnowNot's Avatar
    Join Date
    Jan 2003
    Posts
    792
    No one has answer yet, so I will. I don’t think I can help you, but I am confused. Maybe you could supply more info so someone else can help.

    home network has had an increase of attempted access on different ports. The source IP has been different each time, but stuck to 3 TCP/IP ports
    You only listed one port, 11085. What other ports were “targeted”?

    The destination address was different each time, but the port was the same. ... both the source and destination IP's were different each time.
    What software are you using and how is your network configured that you are receiving traffic not destined for you, or are you using multiple public addresses which were the “target”? Or were the targets private addresses?
    All computers have Norton Internet Security running
    So exactly at what point in the network did you notice these attempts, and where did they come from?
    Did they come from outside the LAN, or inside?
    Were they incoming or outgoing?
    " And maddest of all, to see life as it is and not as it should be" --Miguel Cervantes

  3. #3
    Senior Member
    Join Date
    Nov 2001
    Posts
    4,785
    Source -> Destination
    2454 -> 11085
    4556 -> 11085
    2140 -> 11085

    just seeing this im not sure if 11085 is a local port like your implying of the port for a remote service like msm which i think it may be.

    do a netstat and post it. also download and run fport (from a command prompt), copy and past the results. http://www.foundstone.com/resources/..._detection.htm
    Bukhari:V3B48N826 “The Prophet said, ‘Isn’t the witness of a woman equal to half of that of a man?’ The women said, ‘Yes.’ He said, ‘This is because of the deficiency of a woman’s mind.’”

  4. #4
    Master-Jedi-Pimps0r & Moderator thehorse13's Avatar
    Join Date
    Dec 2002
    Location
    Washington D.C. area
    Posts
    2,885
    Hmmmmm, that port is not registered with the IANA http://www.iana.org/assignments/port-numbers so I'm not exactly convinced it is MSN. Again, your description is not very clear so you'll need to fill in the blanks before anyone can point you in the right direction. How about starting simply with the remote IP address being blocked. We can at least query the WHOIS database to see where the traffic is coming from.

    --TH13
    Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
    Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden

  5. #5
    Senior Member
    Join Date
    Nov 2001
    Posts
    4,785
    th13 i haven't seen the update iana list before. man has that grown but they dont list as far as i can tell any IM services. i dont have msn here at home so im just guessing and until this guy gives us some real information i kind of think that its his computer connecting to a remote service. if he does have a service listening on the port locally an fport should show it
    Bukhari:V3B48N826 “The Prophet said, ‘Isn’t the witness of a woman equal to half of that of a man?’ The women said, ‘Yes.’ He said, ‘This is because of the deficiency of a woman’s mind.’”

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •