PDA

View Full Version : intrusion attempt


dracken1
07-09-2004, 09:28 AM
i use panda antivirus and firewall.
almost everytime i come on the forum an intrusion attempt warning pops up.

just wondering if anyone else gets it.

happens mainly in the late afternoon early evening

Doro
07-09-2004, 09:33 AM
yeah you get this little attacks almost constantly, you'll end up switching the warning thing off (putting the alert on 'silent')

mainly innocent occurences

usually cookies or adware

very rarely hackers

though at any one time you may have several ports open to attack

unless you have upset someone or have sensitive info on your PC then I wouldn't worry

you're safe


shhhhhhhhhhh

Huw Beer Monster
07-09-2004, 09:33 AM
Nope, not seen anything, but then I'm sitting behind work's security.

Try https://www.prevx.com/homeoffice/homeoffice_homedownload.htm for some additional security.

Huw Beer Monster
07-09-2004, 09:35 AM
though at any one time you may have several ports open to attack


Ummm.. you shouldn't have anything open to attack. Ever.

Doro
07-09-2004, 09:36 AM
happens mainly in the late afternoon early evening


either because all the brats are home from school by then, or because adware knows folk are just getting home from work/school

or because it's middle of the day in America

or because it's middle of the night for asia

cue eerie music


yeah, I blame the kids, or is it the parents?

Doro
07-09-2004, 09:39 AM
that's true HUW but my son once scanned my ports from his PC which was several hundred miles away, and reported several of my ports were open, then proceded to take control of my mouse.....brat


dunno how or why, but often some applications leave the port open, some applications do this deliberately for ad cookies etc

there are things to stop it

but mostly it's harmless and not worth worrying about if you have adequate virus software

AVG is a free shareware virus checker, and the best free one there is

dunno the site addy tho

:confused:

Gypsy
07-09-2004, 09:40 AM
yeah i used to use a firewall on broadband ... most of the 'attacks' will be from your own service provider

Huw Beer Monster
07-09-2004, 09:44 AM
AVG is a free shareware virus checker, and the best free one there is

dunno the site addy tho

:confused:

www.grisoft.com will get you there...

blackhack
07-09-2004, 10:56 AM
You should have NO ports open exept the ones your using....

My machines tighter than a ducks arse, but they still try to get root....
If someone elses machine is infected with a trojan/virus, they may not even know themselves that they are at risk, or re-transmitting the virus/worm/trojan.
I continually get hammered by someone here in the uk who has the blaster worm, but my firewall keeps them out...

Ive reported them to thier/my ISP but its still happening...

have a look at my web page for newbies, where you can get anti virus/popup stoppers/firewalls etc...(along with the "fixes" for them)

if anyone needs anything in the way of security, I'm just a pm away....

Rogue Monkey
07-09-2004, 11:21 AM
Which anti virus are u using? I could send ya Norton 2004 if ya want. I avent had any problems. I use zone alarm and norton 2004. never have any problems!

blackhack
07-09-2004, 01:17 PM
For a security test....try this url.....http://scan.sygate.com/

You can go for a complete check up, security wise......

You should have no ports open
you should be invisible to their scan
if it finds open ports it will tell you which ones and how to close them.



you "SHOULD" get this....
Service
Ports
Status
Additional Information
FTP DATA
20
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FTP
21
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SSH
22
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
TELNET
23
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SMTP
25
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DNS
53
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DCC
59
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FINGER
79
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB
80
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
POP3
110
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
IDENT
113
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
NetBIOS
139
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
HTTPS
443
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
Server Message Block
445
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOCKS PROXY
1080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOURCE PORT
1339
BLOCKED
This is the port you are using to communicate to our Web Server. A firewall that uses Stateful Packet Inspection will show a 'BLOCKED' result for this port.
WEB PROXY
8080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.




lets be carefull out there..........

dracken1
07-09-2004, 02:12 PM
thanks black hack
i ran that link
but my firewall blocked it
so all i got was the following

Operating System = Windows XP
Browser = Microsoft Internet Explorer 6.0

Trying to find out your computer name...

Unable to determine your computer name!


Trying to find out what services you are running...

Unable to detect any running services!

Doro
07-09-2004, 02:19 PM
mine's called Nigel

Gypsy
07-09-2004, 02:26 PM
and the results form the kris doro comp is:------

Operating System = Windows XP
Browser = Microsoft Internet Explorer 6.0

Trying to find out your computer name...

Unable to determine your computer name!


Trying to find out what services you are running...

Unable to detect any running services!

dracken1
07-09-2004, 02:57 PM
run the other tests on sygate and got the following

quick scan reports all ports hidden
stealth scan reports all ports hidden
trojan scan was completly blocked
tcp scans all blocked
udp scan returned ,We have determined that you have a firewall blocking UDP ports!

my panda firewall is configured to block an ip address for 10 minutes after an attempted attack if the attack continues it blocks it for another 10.
so i guess it would have been impossible for sygate to get through after the initial attempt

thanks for the link though black hack it does give some peace of mind

blackhack
07-09-2004, 03:00 PM
On the left side of the page are more options.( five other types of scan )..Click of the stealth scan....This will let you know whick ports if any, are open


EDIT..........posting up at the same time Dracken.......lol

Gypsy
07-09-2004, 03:14 PM
looking at the title of this thread again it the subject matter could have been totaly different :D

blackhack
07-09-2004, 06:17 PM
gypsy, can you pass on a message to nigel's master....that if she dont send me her e-mail address, i cant send her the invite.


(this'll get the gossip mongers going....he he he )

Rabid
07-09-2004, 06:37 PM
Thats exactly what i am on RM and i have no probs either m8

Gypsy
07-09-2004, 07:02 PM
gypsy, can you pass on a message to nigel's master....that if she dont send me her e-mail address, i cant send her the invite.


(this'll get the gossip mongers going....he he he )
she said wot bloody invite lmao??

Nitrowing
07-09-2004, 11:01 PM
I use http://www.kerio.com/kpf_home.html and AVG(free) on my systems (and install them on all the systems I service) never had any problems. Had big problems with ZoneAlarm.
This is also excellent - http://www.spybot.info/en/index.html

blackhack
08-09-2004, 07:47 AM
she said wot bloody invite lmao??
for the gmail account.......

Gypsy
08-09-2004, 08:30 AM
have sent ya a PM mate :D

Doro
08-09-2004, 09:04 AM
ooopppsss sorry I forgot about that hinny

told you my brain gets left at home these days

:D

Doro
08-09-2004, 09:05 AM
AND


I didn't swear - I don't do swearing

:D

Gypsy
08-09-2004, 09:09 AM
in that case why did i think for months my name was fuckoff :D