• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

All port scan attack

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> General >> All port scan attack Page: [1]
Login
Message << Older Topic   Newer Topic >>
All port scan attack - 28.Feb.2001 11:28:00 AM   
Yves

 

Posts: 32
Joined: 27.Feb.2001
From: Belgium
Status: offline
hi,

I get this in the event viewer"ISA server detected an all port scan attack from Internet Protocol(IP)X.X.X.X"


The IP address appears to belong to my ISP.

What's wrong?
Is it usual or unusual???

thanks for helping me

Post #: 1
RE: All port scan attack - 28.Feb.2001 2:50:00 PM   
fungusoverlord

 

Posts: 41
Joined: 21.Mar.2001
Status: offline
I am getting that as well. So you are not alone.

(in reply to Yves)
Post #: 2
RE: All port scan attack - 28.Feb.2001 5:26:00 PM   
Sandro Gauci

 

Posts: 68
Joined: 30.Jan.2001
From: Malta
Status: offline
I would recommend looking into your IP Packet filtering log files and check for entries refering to the scanning IP address.

From the MMC snapin you can also choose to log packet data for Packet Filtering logs.

Hope this helps

------------------
Regards

Sandro Gauci,
GFI Security Labs.


(in reply to Yves)
Post #: 3
RE: All port scan attack - 28.Feb.2001 6:36:00 PM   
JasonE

 

Posts: 3
Joined: 15.Feb.2001
Status: offline
I'd wager that your ISP is scanning you for unauthorized services. I know my home network is scanned once or twice a month by my cable provider. The are very adiment about not having servers running.

(in reply to Yves)
Post #: 4
RE: All port scan attack - 5.Jun.2001 6:42:00 PM   
mrdos

 

Posts: 2
Joined: 5.Jun.2001
From: Eagan, MN USA
Status: offline
I have set up ISA server for four customers now and turned on all Intrusion Detection on all four. I leave the default settings except to turn on Intrusion Detection and each of the individual attacks. I leave the default settings for Port Scan attacks (number of ports). On only *one* of these customers, I am getting port scan attacks all of the time from the ISPs servers. I get about 6-10 per day. I have complained to them about it and asked for them to investigate it. They just say "Show us the logs." Which of the three log types have info about Port Scan attacks? Do I need to turn on some extra logging? The times in the log files look wrong. Does it record the time on my server or Universal time or something? I know when the port scan attacks are happening, how many hours do I add or subtract to find the "log" time? I am in CDT.
Thanks for any help,
Jeremy
P.S. BUY THE SHINDERS' BOOK TODAY IF YOU HAVEN'T ALREADY.

(in reply to Yves)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> General >> All port scan attack Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts