home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1899
Discussions: 188,470, Posts: 2,244,181, Members: 232,725
Old July 21st, 2004, 01:04 PM   Digg it!   #1 (permalink)
Ultimate Member
 
woodbutcher's Avatar
 
Join Date: Oct 2001
Location: Chicago
Posts: 2,163
Somebody is scanning your computer

I installed the free version of Sygate's firewall and i'm still in the process of learning the app (alot different then ZA Pro I'd been using) and noticed this fom the app;

Somebody is scanning your computer.
Your computer's TCP ports:
6129, 80, 2745, 3127 and 1025 have been scanned from 24.14.82.83.

Something to be concerneed about?

Also, what the heck is this NDIS User Mode Driver that accesses the net even when it's blocked?

Thanks WB

woodbutcher is offline   Reply With Quote
Old July 21st, 2004, 01:32 PM     #2 (permalink)
Member
 
night_wolf's Avatar
 
Join Date: Jun 2004
Location: Yorktown, VA
Posts: 145
Send a message via AIM to night_wolf
port 6129 usually used by dameware
http://www.linklogger.com/TCP6129.htm

port 80
http://www.nwfusion.com/research/200...spyport80.html

port 2745 back door port commonly used for Bagle/Tanx virus
http://www.linklogger.com/TCP2745.htm

port 3127 back door port commonly used by myDoom/Novar virus
http://www.linklogger.com/TCP3127.htm

port 1025 used for Remote Procedure Call (RPC), can be exploited
http://www.linklogger.com/TCP1025.htm

24.14.82.83, someone was tryin to get in is what it looks like to me

stuff for NDIS...
http://www.ndis.com/faq/QA10290101.htm
http://msdn.microsoft.com/library/de...deiodriver.asp

run a search for 'dameware' as well as getting ad-aware/spybot and see if you find anything

hope this helps


Last edited by night_wolf : July 21st, 2004 at 01:37 PM.
night_wolf is offline   Reply With Quote
Old July 21st, 2004, 01:42 PM     #3 (permalink)
Ultimate Member
 
FatalException's Avatar
 
Join Date: Jun 2004
Location: Indianapolis, Indiana
Posts: 1,386
Sorry I don't know about the NDIS user mode thing, but I think from the look of the ports that someone was likely running a vulnerability scanner like SuperScanner (available from less than reputable sources like various sites on the BOX.SK network). Nothing to be worried about - most of these attacks are random. Once people see that they can't attack you, they move on to easier targets.

FatalException is offline   Reply With Quote
Old July 21st, 2004, 01:54 PM     #4 (permalink)
Anime Otaku
 
RobRich's Avatar
 
Join Date: Oct 2001
Location: Tampa, FL USA
Posts: 105,515
Blog Entries: 15
The NDIS driver is responsible for making calls to dynamic link libraries in the TCP/IP networking stack. NDIS is likely trying to communicate to your ISP's DNS server. There is no need to block NDIS, in fact it is probably not a good idea to block NDIS in certain situations.

If you have WinXP and NDIS is moving a constant flow of data, then you can disable the Wireless Zero Configuration service to stop the data flow. This data is not being transferred to the Internet, but only between a device/app and the NDIS driver. However, Sygate usually thinks the data is being routed to the Internet.

I just checked 24.14.82.83 against the IP address you are using to access TIMO. It appears Comcast is actively scanning for common server ports. This is a common practice and nothing to be concerned about.

Hope this helps,
Robert Richmond
RobRich is offline   Reply With Quote
Old July 21st, 2004, 02:08 PM     #5 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 21,062
This is a reason I don't like ZoneAlarm.. it doesn't tell you information about what's going on outside the box (it may in a log file, but its probably not advertised the log file is there)

While on the other hand until you get Sygate set how you like, it can be a bit of drinking from the firehose
vass0922 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
W32.HLLW.Geobot.gen Virus... How to Remove? PLEASE HELP! mastavic Security and Privacy Issues 3 April 12th, 2004 02:32 AM
What to do with subseven port scan kids? huldu Security and Privacy Issues 2 February 9th, 2004 11:06 AM
Portscan Law? blubomber General Tech Discussion 5 January 20th, 2004 06:01 PM
Spyware really that bad? Telexen General Tech Discussion 7 July 14th, 2003 09:18 PM
Hacker or what? Bob The Great Networking and Internet 12 June 13th, 2002 09:53 PM

Most Active Discussions
Is It Just Me? (3000)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
I think I just killed my computer w.. (26)
Recent Discussions
WD Hard drive reading the wrong.. (1)
P4MAM2-V Mobo Support For Dual .. (1)
can't add picture to this forum (1)
NTVDM CPU has encountered an il.. (8)
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 07:21 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28