Jump to content

ports being attacked.


bantots
 Share

Blockin Ports  

  1. 1. Which ports does your firewall most commonly block?

    • 80
      0
    • 25
      0
    • 1026
      0
    • 443
      0
    • 111
      0
    • 5900
      0
    • other
      0
    • none, I'm not on the internet
      0
  2. 2. How often do my ports get attacked?

    • more than once every few seconds
      0
    • a dozen or so times an hour
      0
    • a few times a day
      0
    • a few times a week
      0
    • hardly once a month
      0
    • never, I don't use firewalls
      0


Recommended Posts

Over the past few days my firewall has been blocking traffic going to port 1026 and 1027 every twenty to thirty seconds, sometimes up to four packets were blocked simultaneously. My question is what use is it for an attacker to attack those ports continuously, is anyone else getting hammered on those ports, and what did you do to stop getting attacked?

Just for the heck of it, I've put a poll here to see if people are getting attacked/scanned on similar ports as me.

Link to comment
Share on other sites

Like Pat, not a clue what my Sygate firewall blocks. Provided it continues blocking in the way I am used to and doesn't let nasties into my machines, that's really all I'm bothered about.

Link to comment
Share on other sites

I never check my ZA logs but since you mentioned it I had a look and a have a LOT of blocked tcp packets coming in on port 445 all from other users on my ISP. After doing a quick online search of what 1026 and 1027 ports, a lot of people have had the same problem. It seems to be messenger spam. If you were to start a packet scan and shut off your firewall you would probably see your computer responding, then an ad/popup of some kind would be sent to your computer. It may or may not popup but you would see it in your packet scan. To find out more you would have to post more about the packets or do a packet scan yourself.

Link to comment
Share on other sites

I think the last time I have checked my ZoneAlarm logs was several years ago. So I really have no idea what ZA is blocking. I know it blocks a lot, but I don't need to know what.

Like Pat, not a clue what my Sygate firewall blocks. Provided it continues blocking in the way I am used to and doesn't let nasties into my machines, that's really all I'm bothered about.

I just leave ZA to get on with it.

Link to comment
Share on other sites

I never check my ZA logs but since you mentioned it I had a look and a have a LOT of blocked tcp packets coming in on port 445 all from other users on my ISP. After doing a quick online search of what 1026 and 1027 ports, a lot of people have had the same problem. It seems to be messenger spam. If you were to start a packet scan and shut off your firewall you would probably see your computer responding, then an ad/popup of some kind would be sent to your computer. It may or may not popup but you would see it in your packet scan. To find out more you would have to post more about the packets or do a packet scan yourself.

Y, the disturbing thing is that a computer running ZA seems to block it. BUT, on a computer with Sygate, it lets the traffic thru. No messenger pop up, I'm aware of that too, but svchost.exe is using port 1026. and when it recieves a packet, svchost.exe also sends something back. I'm not too sure how to change the config on sygate though.

you said you got lots of packets on port 445, how often?

I get four or so packes sent simultaneously from two or three ips every twenty to thirty secs or so since earlier in the week. I'd like to know if this is an attack, or just some normal junk. (note: previously I know I get a few unwanted packets every so often, like a dozen or so blocked things every day, but now I'm getting hundreds per day, and it's just on those ports.)

Link to comment
Share on other sites

I'm fairly certain that nothing has ever been allowed into my machines by laxity on the part of my (Sygate) firewall. I'm quite diligent about keeping unwanted items away and I do regular A/V and other antimalware scans. Nothing ever comes up apart from a few tracking cookies.

Don't take this the wrong way but, be careful not to get into the computer equivalent of "navel contemplation" where you become so concerned about the operation of the machine that you forget or fail to do anything useful with it. :)

Link to comment
Share on other sites

Y, the disturbing thing is that a computer running ZA seems to block it. BUT, on a computer with Sygate, it lets the traffic thru. No messenger pop up, I'm aware of that too, but svchost.exe is using port 1026. and when it recieves a packet, svchost.exe also sends something back. I'm not too sure how to change the config on sygate though.

I can't really comment on Sygate as I have never tried it however with ZoneAlarm you can set rules to block pretty much whatever you want and I'm sure with Sygate you can do the same. Have you allowed messenger to run unrestricted in ZoneAlarm? If not that could be why it doesn't allow packets in at all. The reason Sygate allows it through could be that it was allowed or by default it allows it. It was Microsoft that put out the patch to stop messenger popups so Sygate may not worry about them. The generic process svchost works with many services such as DNS, DHCP, RPC, DCOM, etc... You could just be resolving an address or talking to another program. Is the source address a nonprivate ip (not 192.168.., 169.254..., 10..)? Is the payload (data) readable, or do you know what protocal its using?

you said you got lots of packets on port 445, how often?

I get four or so packes sent simultaneously from two or three ips every twenty to thirty secs or so since earlier in the week. I'd like to know if this is an attack, or just some normal junk. (note: previously I know I get a few unwanted packets every so often, like a dozen or so blocked things every day, but now I'm getting hundreds per day, and it's just on those ports.)

Out of the log entrees that I could see, I was getting one packet sent to my 445 port from around 3 different ips through out that day. There was probably more than 50 but I didn't go farther back. I deleted them all and have been waiting for others to show up. They are most likely attacks because 445 is used for file sharing (SMB). This has long been exploited on Windows machines because people don't take the time to secure their shares. 100s of packets is a lot, too much. If you don't use msn messenger I would uninstall it. Since you posted I've checked my machine and there are a lot of ports that I don't want open or don't use, like 445. I guess I should get to disabling them...

Link to comment
Share on other sites

I don't use messenger or chat clients. The packets are all UDP. ususally, the attacks start within three to five mins after I log onto the internet. And the addresses attacking are in foreign countries.

On the net I found this:

from: http://www.phrack.org/phrack/62/p62-0x03_Linenoise.txt

"It can be seen that when the Windows XP computer sent a UDP packet from

port 1026 to port 53 of the DNS server, the firewall allowed all incoming

UDP traffic to port 1026, regardless of the source IP address or source

port of the incoming traffic. Such incoming traffic was allowed to

continue until the firewall decided to block access to port 1026, which

occurred when there was no incoming traffic to port 1026 for a defined

period of time. This timeframe was between 61 seconds and 120 seconds, as

it appeared that the firewall checked once per minute to determine if

access to ports should be revoked due to more than 60 seconds of

inactivity. Assuming that users connected to the Internet would typically

perform a DNS query at least every minute, incoming access to port 1026

would always be granted. An attacker on the Internet could therefore send

the Windows XP computer spoofed DNS replies without worrying that they

might be blocked by the firewall. Such traffic would not generate any

logs if the firewall was configured to only Log Dropped Packets. If the

firewall was configured to also Log Successful Connections as in this

example, these log entries would disappear among the thousands of other

log entries. Since the firewall logs connections and not traffic, if the

source IP address was set to the Windows XP computer's DNS server, no

extra firewall log entries would be created as a result of the DNS

spoofing attack."

Link to comment
Share on other sites

Thats interesting. Three years later though they probably squashed that bug. At least I hope. A packet scan would show if they were doing that. It sounds like your getting loads of messenger spam. I would do a 20m packet scan and look at what they are sending you. You will probably see packets with a payload of 00 00 00s and packets with text displaying the ad they want to pop up on your computer. If you responded to any of these packets you will get many more. Instead of probing your ports they now know your there and will send more packets along with all the advertisements. All sites said that the packets they recieved came from all over the world as well. I didn't even realize it was this big of a problem till I seen all the pages on google for udp + 1026. I guess a while ago some ISPs were even asked to close them ports. Thats crazy :0

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy