1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

XP Hacker Attack? Sygate Log

Discussion in 'Security and Privacy' started by coop, 2005/09/07.

  1. 2005/09/07
    coop

    coop Inactive Thread Starter

    Joined:
    2005/01/24
    Messages:
    38
    Likes Received:
    0
    I've been noticing every time I glace at my Sygate Firewall icon, it shows an incoming red arrow - meaning it is blocking incoming traffic. In looking at the log, it looks like my computer is being - not port scanned - but getting some traffic ran up against it on a constant basis.

    My port scan log shows no activity, but my traffic log is littered with this:
     
    coop,
    #1
  2. 2005/09/07
    oshwyn5

    oshwyn5 Inactive

    Joined:
    2005/08/25
    Messages:
    736
    Likes Received:
    0
    I would not be concerned, that is just a firewall doing its job and doing it well.

    No need to have it warn you of every misdirected packet, every probe for an open port by a spammer bot etc. They are not attacking you, they are just running through IP blocks and looking for open un patched and unprotected machines.
    Notice how there are several with close IPs?
    for example.

    These represent a block scanned by a worm or hacker and all those machines were vulnerable and became infected and are now zombies carrying on the search.

    It may be a network aware worm, or spambot .

    Just keep your firewall on and up to date. It is not you, that is the target, it is anyone on the internet. The internet is a dangerous place these days.

    Zombie machines are used to send out mass mailings either of worms or spam. They generally connect back by opening a specific port on which additional instructions are delivered.
     

  3. to hide this advert.

  4. 2005/09/07
    coop

    coop Inactive Thread Starter

    Joined:
    2005/01/24
    Messages:
    38
    Likes Received:
    0
    Thank you! I suspected that was possible, but I wanted to make sure. Thanks again!
     
    coop,
    #3

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.