![]() |
|
#1
|
||||
|
||||
|
hey everyone
last night i noticed my firewall icon blinking so i click up the security log and it said someone scanning ports so i do a backtrace and it gave this message:% objects are in RPSL format.what does this mean? thanks Rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#2
|
|||
|
|||
|
Rita, try www.dnsstuff.com, it's website can trace the IP address of the person who scanned you.
I also have been getting several port scans these days, anyway all my ports are stealthed out 100%. Eg: Somebody is scanning your computer. Your computer's TCP ports: 2745, 5000, 6129, 3140 and 80 have been scanned from ********** |
|
#3
|
||||
|
||||
|
Not an expert on this stuff, but here is what I believe is happening. When you did a trace, the IP if the intruder is looked up in a Internet Registry. The data displayed is in a format known as RPSL, or Routing Policy Specification Language. See here and here.
__________________
Daisey Sean Connery: "Scotch, straight up. Any Single Malt will do." |
|
#4
|
||||
|
||||
|
Quote:
i traced the ip address for both that were scanning ports and they were earthlink network and enjoy world from Seoul Korea--thanks for the link.what does this mean?is it important?excuse my ignorance but if firewall is flashing have these scans been blocked? thanks Rita Rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#5
|
||||
|
||||
|
Quote:
thanks for link i went and read it but im afraid i didnt really understand any of it.i have so much to learn sometimes its overwhelming.thank you for trying to help someday i will understand i promisethanks Rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#6
|
||||
|
||||
|
Hi Rita
If you are ever curious about the IP's showing up in your firewall logs, it is better to use one of the online lookup sites like nadirah linked to. If you do these querries via options in your firewall and on your own system, some of these lookups and traceroutes will result in your system contacting the system being querried and you could end up showing up in their logs (so much for stealth if you are concerned about that). Quote:
Quote:
Regards, CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks." - Bruce Schneier |
|
#7
|
|||
|
|||
|
Quote:
Yes, any firewall will block these scans. More importantly, make sure all your ports are either blocked/stealthed. |
|
#8
|
|||
|
|||
|
A good site for look up is
http://centralops.net/co/DomainDossier.aspx It gives options of databases; often if one doesn't have it the other does. |
|
#9
|
||||
|
||||
|
Quote:
thank you for your reply and if i do any more traces i'll use an online lookup site that Nadirah linked me to as you said.--is there really any benefit to doing a backtrace if the firewall has blocked them other than just curiosity?I have never used a firewall till about 2 weeks ago so i dont know much about them thanks rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#10
|
||||
|
||||
|
Quote:
hi thank you for the link--i'll check it out Rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#11
|
||||
|
||||
|
dear ritaann, portscans are very common and most of the time harmless when you're using a good firewall. so no need to lose sleep over this matter unless you have a regular visitor. most people select a random block for portscan and if for some reason someone is hellbent on your IP then you should report this attack to his/her ISP. try to hide your IP as much as you can specially if you're using a static one. most ISPs doesn't tolerate portscanning so i'm sure there will be some action.
__________________
If it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic. ~ Twiddledee |
|
#12
|
||||
|
||||
|
Quote:
hi crazym could you tell me about executable files?firewall was flashing and i looked at the security log and it was an executable file outgoing from a spyware scanner i have(a squared two)that was blocked.what does this mean?anything? thanks rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#13
|
||||
|
||||
|
Quote:
Quote:
Regards, CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks." - Bruce Schneier |
|
#14
|
||||
|
||||
|
Quote:
Hi CrazyM yes,this program does have an update feature and i have already checked yes to allow it to access internet when the firewall prompted me one day and i clicked yes not to ask me again.but i bet its what it is anyway.thanks so much for your reply Rita
__________________
Don't smoke too much, drink too much, eat too much or work too much. We're all on the road to the grave -- but there's no need to be in the passing lane." |
|
#15
|
||||
|
||||
|
Hey all
I've been reading all the posts and must say that you guys are full of great advice! I was just wondering where to go to test my firewall? Thanx a bunch! Last edited by mismis29 : August 16th, 2004 at 10:28 PM. Reason: to enable e-mail notification |
|
#17
|
||||
|
||||
|
Thanx for the suggestion! I'll give it a try.
|
|
#18
|
||||
|
||||
|
Hi mismis29.... yes that GRC site listed by Devinco
is very good, it was probably one of the first out there.There are 3 main tests you can take there. File Sharing, Common Ports and All Service Ports. Also check to see if you can be Messenger Spammed, and Browser Headers info. Also, you may like to try this lot out in THIS Thread. I've listed a lot of sites for various tests, etc. including AV's, Browsers, Firewalls. Have fun. ![]() Cheers, TAS
__________________
I'm feeling much better now since all the other people in my head and I, are working as a team! |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|