Port scans. What are these?

Port scans. What are these?

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Port scans. What are these? kmtanner 10-18-2005
Posted by on October 18, 2005, 9:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi people. I get constant & regular port scans from these IP
addresses:

61.137.117.208
61.233.40.205
61.237.29.102
61.237.3.70
61.235.144.86

Severity: Minor
Direction: Incoming
Protocol: UDP

ARIN and RIPE whois servers don't give any information about any
of these addresses. It kinda bugs me because they're constant
scans. Probably caused by some application I've installed (like
automatic update check or...)

Could anyone enlighten me? Thanks in advance.



Posted by Anders on October 18, 2005, 5:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
kmtanner@cyberspace.org wrote:
> Hi people. I get constant & regular port scans from these IP
> addresses:
>
> 61.137.117.208
> 61.233.40.205
> 61.237.29.102
> 61.237.3.70
> 61.235.144.86
>
> Severity: Minor
> Direction: Incoming
> Protocol: UDP
>
> ARIN and RIPE whois servers don't give any information about any
> of these addresses. It kinda bugs me because they're constant
> scans. Probably caused by some application I've installed (like
> automatic update check or...)
>
> Could anyone enlighten me? Thanks in advance.
>

It looks like it is China messenger spam to me, are they using udp on
port 1026,1027 it probable is.

61.137.117.208
61.137.0.0 - 61.137.127.255
netname: CHINANET-HN
country: CN
descr: CHINANET Hunan province network
descr: China Telecom

61.233.40.205
61.233.40.0 - 61.233.40.255
netname: CRHbYqS
country: CN
descr: China Railcom Hebei Yangquan Subbranch
descr: Telecommunication

61.237.29.102
61.232.0.0 - 61.237.255.255
netname: CRTC
country: CN
descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER
admin-c: LQ112-AP
tech-c: LM273-AP
status: ALLOCATED PORTABLE

61.237.3.70
61.232.0.0 - 61.237.255.255
netname: CRTC
country: CN
descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER
admin-c: LQ112-AP
tech-c: LM273-AP
status: ALLOCATED PORTABLE

61.235.144.86
61.232.0.0 - 61.237.255.255
netname: CRTC
country: CN
descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER
admin-c: LQ112-AP
tech-c: LM273-AP
status: ALLOCATED PORTABLE


Posted by on October 18, 2005, 11:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Anders wrote:
> kmtanner@cyberspace.org wrote:
[...]
> It looks like it is China messenger spam to me, are they using udp on
> port 1026,1027 it probable is.

This is the information I got:

=============insert
Somebody is scanning your computer.
Your computer's UDP ports:
1028, 1029, 1030, and 4081 have been scanned from 61.137.117.208..
=============outsert

Thanks a lot for your help.



Posted by on October 18, 2005, 11:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Oh btw Anders: What service did you use to get the information? RIPE
doesn't
work well for me...



Posted by Hairy One Kenobi on October 18, 2005, 11:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Oh btw Anders: What service did you use to get the information? RIPE
> doesn't
> work well for me...

There are more than two rings in the Olympic symbol (hint!)

Google for APNIC, then either follow that up with a more general registrar
search, or download the appropriate software.

I cook my own, but many are available. codecutters.org. YMMV, I don't
exactly stay up nights doing wonderful and interesting things with
interfaces (Erm.. /software/ interfaces, that is. Cough! :o)

--

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!




Similar ThreadsPosted
How do firewalls react to UDP port scans? September 30, 2006, 10:09 pm
How to report 38 port scans in 1 week from 7.12.12.16 (part of nic.mil)? March 24, 2006, 5:17 am
Stopping Quick Scans After Definitions Update on SAV10.0.2 March 31, 2006, 3:54 am
FTP SSH port forwarding December 27, 2006, 1:02 pm
Port scanned by these strange IPs... November 21, 2005, 7:09 pm
cant close or cloak port 305 win 2k December 10, 2005, 6:10 pm
Source Port 10000 March 10, 2006, 9:39 am
Identifying Apps By Port December 18, 2006, 3:20 pm
port=1026&reason=ICMPsent November 14, 2005, 4:36 pm
Port forwarding/open ports? January 30, 2006, 2:51 pm

The site map in XML format XML site map

Contact Us | Privacy Policy