Crazy port scanning attack.

Discussion in 'other firewalls' started by nadirah, Dec 2, 2004.

Thread Status:
Not open for further replies.
  1. nadirah

    nadirah Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    3,647
    My sygate personal firewall blocked this crazy port scan. I got a shock when my firewall continuously alerted me for a rather long time that I was under attack. I've never seen such a port scan that would carry on longer than usual. Most port scans i get only last for 2 seconds then they stop. But this one from Pair Networks went on continuously! Would you believe it?
    The port scan came from:

    216.92.0.0 - 216.92.255.255

    Pair Networks
    4100 Butler St
    Pittsburgh PA 15201, USA.

    Take a look for yourself. To those people at Pair Networks, I will REPORT you to my ISP if you attack me one more time, just wait and see. I WILL NOT tolerate anybody who attacks me in this manner.
    :mad:
     

    Attached Files:

    Last edited: Dec 2, 2004
  2. nadirah

    nadirah Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    3,647
    grrrrrrr........ :mad:
     

    Attached Files:

    • bobm.GIF
      bobm.GIF
      File size:
      35.3 KB
      Views:
      209
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    17,058
    Hi nadirah

    Pair Networks
    4100 Butler St
    Pittsburgh, PA 15201

    Kevin Martin
    Sigma(at)pair(dot)com


    I'd bet it is someone's computer that is infected and the user is clueless. I'd contact pair as it is one of their users.

    Pete
     
  4. nadirah

    nadirah Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    3,647
    The attack always starts from here: http://www.all-nettools.com/toolbox
    It only happens upon clicking this button:
    I suspect this website may be the source of this attack.
     

    Attached Files:

  5. FluxGFX

    FluxGFX Registered Member

    Joined:
    Jan 23, 2003
    Posts:
    667
    Location:
    Ottawa/Canada
    Quote from the website


    "WARNING: If you run some of the tools listed below on your own IP address, your firewall or intrusion detection system may inform you on a "port scan" or "network attack" originating from qs153.pair.com (216.92.131.153). This is the return traffic from the traceroute or ping that you initiated rather than an intrusion attempt. Please keep this in mind when you analyze your firewall logs and think twice before e-mailing the network administrator, as we receive frequent complaints from newbies who think that someone is trying to break into their PCs. Thank you. "
     
Loading...
Thread Status:
Not open for further replies.