CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Getting worried about ammount of port scans

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
mutabaruka

Cadet
Cadet


Joined: Aug 11, 2007
Posts: 1
Location: USA

PostPosted: Sat Aug 11, 2007 4:51 am    Post subject: Getting worried about ammount of port scans
Reply with quote

first of all I am not a network engineer. My network has been under a heavy port scan for a couple of days. It started at low ports and now is up into the 61000 range. I wasn't concerned at first because my SonicWall drops the scan plus it is not uncommon to have a few scans here and there but closer look shows that the scans have increased and are now less than 1 minute apart sometimes I get three different block scans on the same connection. my log file is filling up and now it is starting to bother me. I feel like someone is circling just waiting for a port to open.

I have contacted the NOC of the source IP and my ISP's NOC. I have sent a 4 hour log to them.

Question 1 is, Do I accept this nonsense and just let my log files pile up or is there a way to just block the source IP from making any connection WHATSOEVER without addin any extra hardware?

Is there anything I can to to counter the attack? (I am like that, you hit me and I hit back harder)

thx.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Mon Aug 13, 2007 4:25 pm    Post subject:
Reply with quote

Countering the attacks with a counterattack is inappropriate, and your ISP might do something about that - like terminate your service, for example. It's frustrating, but keep reporting the attackers and sooner or later, their ISP might deign to do something.

Your SonicWALL is already blocking those incoming packets, so that's not really the issue. Your issue is with your logs filling up, and can be fixed by temporarily turning off logging of attacks while this is going on. The issue with that is your documentation that this is happening then disappears, and I would think you would want that documentation to keep reporting it to your attackers' ISP(s).


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Scott_Hollingsworth

Sergeant
Sergeant
Premium Member

Joined: May 09, 2006
Posts: 116
Location: USA
Premium

PostPosted: Wed Aug 15, 2007 12:07 am    Post subject: Some Ideas
Reply with quote

Auto log archival? If the feature is available, then evidence can be preserved.

As mentioned direct retaliation is not a good idea, not at all.

Have you ever heard of a tarpit? Basic concept is to purposely delay valid responses to probe packets to the maximum technically possible. It can slow a probe to a crawl. But there are tarpit countermeasures also. You need to have a good understanding of what's going on because you could open yourself up inadvertently when trying to implement a tarpit.

I have to assume you current protection is simply ignoring the probe packets which is the safest course. The tarpit concept requires responding which can in itself reveal too much info if the attacker is skilled.

A tarpit is an acceptable "retaliation" because it is doing nothing more than providing a delayed response to a query. It is somewhat passive in a sense. Anything more is not really acceptable.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer