PDA

View Full Version : ho chiuso le porte sul router e portscan!


angmail
25-03-2007, 21:58
Salve, sono possessore del router netgear dg834 e ho letto che bisognava bloccare i servizi in ingresso visto che non sono bloccati di default.

Li ho bloccati e guardate il mio registro del router:

Sun, 2007-03-25 22:50:41 - UDP Packet - Source:58.241.133.147,58402 Destination:84.220.141.40,1027 - [Any(UDP) rule match]
Sun, 2007-03-25 22:50:41 - UDP Packet - Source:58.241.133.147,58829 Destination:84.220.141.40,1027 - [Any(UDP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6153 Destination:84.220.141.40,31 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6155 Destination:84.220.141.40,41 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6157 Destination:84.220.141.40,58 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6159 Destination:84.220.141.40,146 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6161 Destination:84.220.141.40,531 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6163 Destination:84.220.141.40,555 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6165 Destination:84.220.141.40,666 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6167 Destination:84.220.141.40,911 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6169 Destination:84.220.141.40,999 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6171 Destination:84.220.141.40,1001 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:55 - TCP Packet - Source:206.204.51.132,6173 Destination:84.220.141.40,1010 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6175 Destination:84.220.141.40,1011 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6177 Destination:84.220.141.40,1012 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6179 Destination:84.220.141.40,1015 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6181 Destination:84.220.141.40,1024 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6183 Destination:84.220.141.40,1025 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6185 Destination:84.220.141.40,1026 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6187 Destination:84.220.141.40,1027 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6189 Destination:84.220.141.40,1028 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6191 Destination:84.220.141.40,1029 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6193 Destination:84.220.141.40,1030 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6195 Destination:84.220.141.40,1042 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6197 Destination:84.220.141.40,1045 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6199 Destination:84.220.141.40,1090 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6201 Destination:84.220.141.40,1234 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6203 Destination:84.220.141.40,1243 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:56 - TCP Packet - Source:206.204.51.132,6205 Destination:84.220.141.40,1492 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6207 Destination:84.220.141.40,1600 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6209 Destination:84.220.141.40,1807 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6211 Destination:84.220.141.40,1981 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6213 Destination:84.220.141.40,1999 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6215 Destination:84.220.141.40,2000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6217 Destination:84.220.141.40,2001 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6219 Destination:84.220.141.40,2002 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6221 Destination:84.220.141.40,2003 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6224 Destination:84.220.141.40,2004 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6227 Destination:84.220.141.40,2005 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6230 Destination:84.220.141.40,2023 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6233 Destination:84.220.141.40,2115 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6236 Destination:84.220.141.40,2140 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6239 Destination:84.220.141.40,2565 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6242 Destination:84.220.141.40,2583 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:57 - TCP Packet - Source:206.204.51.132,6244 Destination:84.220.141.40,2773 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6246 Destination:84.220.141.40,2774 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6248 Destination:84.220.141.40,2801 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6250 Destination:84.220.141.40,3024 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6252 Destination:84.220.141.40,3129 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6255 Destination:84.220.141.40,3150 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6257 Destination:84.220.141.40,3700 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6259 Destination:84.220.141.40,4092 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6260 Destination:84.220.141.40,4267 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6262 Destination:84.220.141.40,4567 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6264 Destination:84.220.141.40,5000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6267 Destination:84.220.141.40,5001 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6269 Destination:84.220.141.40,5321 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6270 Destination:84.220.141.40,5400 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6272 Destination:84.220.141.40,5401 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6274 Destination:84.220.141.40,5402 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:58 - TCP Packet - Source:206.204.51.132,6276 Destination:84.220.141.40,5555 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6278 Destination:84.220.141.40,5556 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6280 Destination:84.220.141.40,5557 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6282 Destination:84.220.141.40,5569 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6284 Destination:84.220.141.40,5742 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6287 Destination:84.220.141.40,6400 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6290 Destination:84.220.141.40,6670 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6292 Destination:84.220.141.40,6771 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6294 Destination:84.220.141.40,6776 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6297 Destination:84.220.141.40,6939 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6300 Destination:84.220.141.40,6969 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6303 Destination:84.220.141.40,6970 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6306 Destination:84.220.141.40,7000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6309 Destination:84.220.141.40,7215 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6312 Destination:84.220.141.40,7300 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6315 Destination:84.220.141.40,7301 - [Any(TCP) rule match]
Sun, 2007-03-25 22:50:59 - TCP Packet - Source:206.204.51.132,6318 Destination:84.220.141.40,7306 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6321 Destination:84.220.141.40,7307 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6324 Destination:84.220.141.40,7308 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6327 Destination:84.220.141.40,7597 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6330 Destination:84.220.141.40,7789 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6333 Destination:84.220.141.40,9872 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6336 Destination:84.220.141.40,9873 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6339 Destination:84.220.141.40,9874 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6341 Destination:84.220.141.40,9875 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6343 Destination:84.220.141.40,9989 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6345 Destination:84.220.141.40,10067 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6347 Destination:84.220.141.40,10167 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6349 Destination:84.220.141.40,10520 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6351 Destination:84.220.141.40,10607 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6353 Destination:84.220.141.40,11000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6355 Destination:84.220.141.40,11223 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:00 - TCP Packet - Source:206.204.51.132,6357 Destination:84.220.141.40,12076 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6359 Destination:84.220.141.40,12223 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6361 Destination:84.220.141.40,12345 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6363 Destination:84.220.141.40,12346 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6365 Destination:84.220.141.40,12361 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6367 Destination:84.220.141.40,12362 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6369 Destination:84.220.141.40,12363 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6371 Destination:84.220.141.40,12631 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6373 Destination:84.220.141.40,13000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6375 Destination:84.220.141.40,16959 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6377 Destination:84.220.141.40,20034 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6379 Destination:84.220.141.40,21554 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6381 Destination:84.220.141.40,22222 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6383 Destination:84.220.141.40,23456 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6385 Destination:84.220.141.40,23476 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6387 Destination:84.220.141.40,23477 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:01 - TCP Packet - Source:206.204.51.132,6389 Destination:84.220.141.40,26274 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6391 Destination:84.220.141.40,27374 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6393 Destination:84.220.141.40,30100 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6395 Destination:84.220.141.40,30101 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6397 Destination:84.220.141.40,30102 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6399 Destination:84.220.141.40,31337 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6401 Destination:84.220.141.40,31785 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6405 Destination:84.220.141.40,31787 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6408 Destination:84.220.141.40,31788 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6411 Destination:84.220.141.40,31789 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6414 Destination:84.220.141.40,31791 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6417 Destination:84.220.141.40,31792 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6420 Destination:84.220.141.40,40421 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6423 Destination:84.220.141.40,40422 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6426 Destination:84.220.141.40,40423 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6429 Destination:84.220.141.40,40425 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:02 - TCP Packet - Source:206.204.51.132,6432 Destination:84.220.141.40,40426 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:03 - TCP Packet - Source:206.204.51.132,6435 Destination:84.220.141.40,54283 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:03 - TCP Packet - Source:206.204.51.132,6438 Destination:84.220.141.40,54320 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:03 - TCP Packet - Source:206.204.51.132,6442 Destination:84.220.141.40,54321 - [Any(TCP) rule match]
Sun, 2007-03-25 22:51:03 - TCP Packet - Source:206.204.51.132,6446 Destination:84.220.141.40,60000 - [Any(TCP) rule match]
Sun, 2007-03-25 22:54:47 - TCP Packet - Source:84.220.128.140,2305 Destination:84.220.141.40,139 - [Any(TCP) rule match]

vorrei capire č un attacco dall'esterno o ho qualche spyware che dall'interno ce sta a provā?
ho fatto analisi port scan tutto ok, hijack eliminato i dubbi e scansione con norton online tutto ok, cosa posso fare ancora?
come posso capire? l'ip che mi sniffa č cinese...pare..