Re: ISA Server detected an all port scan attack

From: Matt Gibson (mattg_at_blueedgetech.ca)
Date: 06/02/04


Date: Wed, 2 Jun 2004 10:14:15 -0700

My comments are inline.

"Des" <anonymous@discussions.microsoft.com> wrote in message
news:AD9AFD08-896A-4393-A8A4-55F591B94A0F@microsoft.com...
> Is there any way I can find out what causes these things, and how to stop
them..

Someone's doing a port scan on your machine...there's nothing you can do to
stop that. If you want to stop recieving the notices as often, if you right
click on "Packet Filters" in the ISA MMC, you can set the thresholds for
when it will e-mail you, or you can turn that off all together.

> I get at least 5 different addresses a day, and a couple of them get to my
inbox over 15 times a day.

Isn't the internet safe and fun?

> heres one - ISA Server detected an all port scan attack from Internet
Protocol (IP) address 64.191.159.133.
>
> I can do a whois, but that doesnt even tell me much on who they are.

If ISA's notifying you, and ISA's properly configured, and the server is
patched, I wouldn't worry about it.

> Thanks.

-Matt



Relevant Pages

  • Re: Irritating DSL annoyance
    ... Your fw needs to _allow_ traffic in headed for its IP and port#. ... "Which whois _server_ are you ... you will get packets "directed" to your IP/ports. ... Even if it's just some "kids" playing around, ...
    (comp.os.linux.misc)
  • Re: MS ActiveSync 4.2 problem
    ... But still AS doesnt recognize the device. ... Until you get the connection fixed, nothing can happen to your contacts ... Checked all services, still doesnt work ...
    (microsoft.public.pocketpc.activesync)
  • Re: Problem linking MySQL 4.1.11 via FreeBSD 4.10 ports
    ... * After rebuilding the linuxthreads port to make sure the library is ... /* Definition for inline version */ ... so I can see that gcc 2.95 and gcc 3.3 would be handled quite ... I'd really rather not have to upgrade the compiler toolchain just to ...
    (freebsd-questions)
  • Abuse reporting based on whois
    ... an process to report this abuse to the ISP's who own the source IP ... then I read the sorted file and do an whois ... for about 30% of the abusive port scan traffic being blocked. ... nothing to report all the port targeted packet traffic. ...
    (freebsd-isp)
  • Re: Question About Firewalls and Hacking
    ... We must find a way to do this without paying $4500 for hardware firewall ... > has some service/application listening on it there is little chance ... If the service that is listening to port 1000 have some kind of ... Just because I dont, doesnt mean I cant. ...
    (comp.security.firewalls)