PDA

View Full Version : hacker on the Port bow!


Louis
06-19-2005, 11:40 PM
Hey Folks.

I keep getting this IP address trying to get through a variety of ports

65.39.211.138.

This time it tried port 2718 but has attempted quite a few others 1493, 2714, 3935. I traced it to Vancouver, Peer 1 Network Inc, and Bravenet Web Services but no info on the registrant. Any idea on what this is?

Don-Dad
06-20-2005, 01:26 AM
Bravenet is a popular service, it offers free guestbooks, forums, etc.. I'm not sure if this is the same bravenet but if you visit any places that use their service, that could be the culprit. I'm no expert in hacking and can't offer off much more advice :)

tt3
06-20-2005, 02:56 AM
I think the site is pcpitstop.com that helped me with my adware issues. They had a good forum with a lot of pro's donating their time to help the eedjits like me. Probably mumbling under their breath "another I dee ten T error"
;)
I'll check downstairs to make sure I got the right sitename and get back to you.

Louis
06-20-2005, 03:02 AM
Ok... but I guess I didn't phrase the question correctly. Given the amount of times this particular IP address is thying to get in, could it be malicious or is it some part of a regular service (banner ad, sub service of comcast whatever) trying to establish a link?

tt3
06-20-2005, 04:18 AM
Nope, I totally understood your phrasing (I think). I was suggesting dropping by said site (which I haven't confirmed) to see what they say about your question. ;) From what little I gathered about it, its a community of security proffesionals trying to help the little guy. They'd probably have a quick answer if it hadn't been answered already.
Cheers!
8)

Don-Dad
06-20-2005, 04:48 AM
I assume if your using comcast you have a cable modem connection? Do you use a router with a firewall?

If yes, that's good :) I use a router w/ firewall and also zone alrms free firewall on each individual pc, double secret security measures, haha!

Jackson's Dad
06-20-2005, 01:28 PM
As long as they are not getting through, you are ok. If you look at those firewall logs a lot, you'll see tons of similar "attacks". Do you run any software on your site? (Message boards, email, etc.) If so, BE SURE that it is all up to date. I had a stats program on my site that was out of date, and had an old security hole -- sure enough, my site got hacked one day.

GoatBeard
06-20-2005, 02:37 PM
www.dslreports.com has some nifty tools to check your security, connection speed, etc.

Go to the tools section.

Louis
06-20-2005, 02:59 PM
I assume if your using comcast you have a cable modem connection? Do you use a router with a firewall?

Great answers guys, thanks. Don you asked if I use a router with a firewall.... I have a router which runs both Voip and the PC (I only use one PC). The PC has a firewall from McAffee (gotta dance with the devil sometime) which I've tested from a variety of sources and seems impermeable to most. I did get an interesting email once from a antispyware company highlighting my IP address so it's not perfect.

I currently run three antispy/antivirus programs each scheduled to clean at different times. Mcaffee full spectrum (spamkiller disabled) , Spyware Doc and Yahoo Antispy.


UPDATE: COOL! used the dslreports.com website and though they had my IP address they couldn't break through the firewall. both TCP and UDP were filtered ](*,)

Don-Dad
06-20-2005, 05:34 PM
Might not hurt to get a router with a NAT firewall, they are getting very cheap, probably pick one up for less that $50.00.

Louis
06-20-2005, 07:46 PM
not questioning your sound judgement Don but whould a firewall on the router be necessary if I had another pc without one?

Don-Dad
06-20-2005, 08:33 PM
router with firewall is just another security precaution. Nothing is necessary but I'm more on the "better safe than sorry" end of the spectrum.