Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 12th December 2006   #1
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


Unhappy Mirc [Sygate reports port scan attack while logging on]

Hi whilst logging into MIRC sygate firewall is telling me this:

port scan attack

Somebody is scanning your computer.
Your computer's TCP ports:
28882, 10000, 58, and 6000 have been scanned from 207.182.243.125..

what is this please?

thanks
Claudine

bombagirl is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 12th December 2006   #2
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 17,279
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Claudine

Please observe Posting Rules #3 - Meaningful Subject - I have adjusted your title.

PeteC is offline   Reply With Quote
Old 12th December 2006   #3
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hello Claudine,

looking up the IP address here: http://www.arin.net/whois/

Comes up with Velocity Networks as the owner of IP address.

This is a scan of systems across a network by someone that uses Velocity Networks, looking for open ports. May or may not be malicious. ISP's and Network admins scan networks as a security measure. Hackers use scans to find vulnerable systems with open ports.

In either case, Sygate is doing it's job by blocking the reported ports.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 12th December 2006   #4
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


I don't get it....what did I do wrong???? can someone help me with this at least please?

Charles what can I do to check whether this is malicious or not? can I block it somehow?

bombagirl is offline   Reply With Quote
Old 12th December 2006   #5
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Quote:
Originally Posted by bombagirl
Charles what can I do to check whether this is malicious or not? can I block it somehow?
Hi Cloudine,

Sygate is blocking it. You can't stop the scans themselves, only block them. I wouldn't worry about it.

If it is malacious, then most likely its an infected system with a trojan that's looking for others to infect. Can't really tell unless there are a lot of these scans and with a pattern of about the same time(s) during the day. That's an indication of someone turning on their system around the same time daily.

Quote:
Originally Posted by bombagirl
I don't get it....what did I do wrong????
Pete was reacting to your thread title - we encourage meaningfull tiltles so that others searching with this or similiar problem will come upon your thread. I was going to change your title but Pete beat me to it.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 12th December 2006   #6
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


Quote:
Originally Posted by charlesvar
Hi Cloudine,

Sygate is blocking it. You can't stop the scans themselves, only block them. I wouldn't worry about it.

If it is malacious, then most likely its an infected system with a trojan that's looking for others to infect. Can't really tell unless there are lot of these scans and with a pattern of about the same time(s) during the day. That's an indication of someone turning on their system around the same time daily.


Regards - Charles
still didn't get it....sorry...there was no indication that sygate blocked it....port scan attack is logged....that doesn't showe it is being blocked no?

someoen told me that people can get your ip ad....what is it? they stole money from his internet banking...he thinks people from mirc chatting...what is this please? how can this happen? does this mean I must stop using mirc?

bombagirl is offline   Reply With Quote
Old 13th December 2006   #7
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Quote:
Originally Posted by bombagirl
still didn't get it....sorry...there was no indication that sygate blocked it....port scan attack is logged....that doesn't showe it is being blocked no?
It is being blocked - the forewall is logging the scan for your information; as a former user of Sygate I can attest to that. And every firewall does the same thing.

Quote:
Originally Posted by bombagirl
someoen told me that people can get your ip ad....what is it? they stole money from his internet banking...he thinks people from mirc chatting...what is this please? how can this happen? does this mean I must stop using mirc?
Your IP address is public knowlege - look in Sysgate's logs for yours under destination I think.

What got stolen is the password(s) to access the account(s). Not the user's IP address which doesn't get you anywhere unless the system is unprotected. The means to steal the passward is done either thru a fraudulant email pointing to a bad website or a trojan got onto the system. In either case, it came thru the Browser, not the firewall.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 13th December 2006   #8
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


No I don't mean through the firewall but through MIRC....the chatting program
bombagirl is offline   Reply With Quote
Old 13th December 2006   #9
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


I don't know anything about MIRC, so can't pass judgement about it's safety. A quick search on it doesn't come up with any major alarms. There are, as in any software, holes and bugs. There are specific downsides the way scripting is used in an earlier version - see http://en.wikipedia.org/wiki/MIRC
Quote:
mIRC scripting allows troublemakers to dupe naive users into running malicious code merely by typing things in the chat window (for example, entering lines beginning with //write $decode(). Since version 6.17 this is disabled by default, and various other commands considered dangerous can be locked in mIRC options
In the meantime, list the security software you're using and we'll see if there is anything to add or substitute to make your system more secure.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 13th December 2006   #10
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


I'm using sygate personal firewall, ewido anti spyware, spybot and f-prot antivirus
bombagirl is offline   Reply With Quote
Old 13th December 2006   #11
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hi Cloudine,

Good security programs and I would not substitute anything else.

There are additional measures you can take. Read TeMerc's recomendations on security in post #2 here:
security results

SpywareBlaster and IESPY ADS use very little resources and provide an extra layer of protection.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 13th December 2006   #12
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


ok thanks a lot Charles
bombagirl is offline   Reply With Quote
Old 13th December 2006   #13
Senior Member
 
Profile:
Join Date: Aug 2006
Location: Malta (Europe)
Posts: 124
Computer Experience:
Intermediate
bombagirl Reputation Level


Quote:
Originally Posted by charlesvar


IESPY ADS use very little resources and provide an extra layer of protection.

Regards - Charles
what is the "IESPY ads" tried to look for that program but didn't find any

bombagirl is offline   Reply With Quote
Old 13th December 2006   #14
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 17,279
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

http://www.spywarewarrior.com/uiuc/resource.htm
PeteC is offline   Reply With Quote
Old 13th December 2006   #15
WindowsBBS Team Member
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,309
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hi Claudine,

For future reference, in that thread's post #2 for which I gave you the url for - TeMerc's reference to IESPY ADS is highlighted in blue which means clicking on it takes you to the same place that Pete's url does.

Regards - Charles

charlesvar is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
What is supposed to be in Win Xp Home missmissy Windows XP 84 5th December 2004 14:22
dNS And port scan Sue Networking 5 20th February 2003 17:22
(XP IE6) Cannot log into secure pages - loops Judy Internet Explorer 33 14th February 2003 22:28
Local Network / Firewall Kerio a.ruiter Networking 15 27th September 2002 22:34
iRC client Spete General Internet 3 18th September 2002 15:34


All times are GMT +1. The time now is 05:49.






Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2008 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[
]