Re: Intrusion Attempts ?



It probably is an intrusion attempt, but nothing to worry about, as long as
you have not left any doors open.

What some hacker here has done here, is attempted to connect to a large
number of ports between 1 & 2048. Probably all ports, probably logged
somewhere, and probably thousands of other random IP addresses. Mr Hacker
now knows what ports you have open. From this he can probably deduce that
you are running an SBS server, and how your mail is configured. He also has
a list of other IPs, and the ports they have open.

>From here, he can try a variety of attacks. If ports 135, 138, 139 or 445
are open, you have a big problem, as a netbios connection can be made. If
port 25 is open, a relay attack may be attempted. Someone may observe you
are running Exchange, and attempt a dictionary realy attack on port 25.

What has happend sop far is akin to someone walking down the street &
looking for open front doors. This kind of thing is to be expected.

Mal Osbonre
MCSE MVP Mensa



"Gary D" <gary@xxxxxxxxxxxxxxxx> wrote in message
news:eLy3mkkfFHA.3940@xxxxxxxxxxxxxxxxxxxxxxx
>I have a SBS2000 system and daily receive the following ISA server
>intrusion notifications.
>
> ISA Server name: ABCSERVER
> ISA Server detected a well-known port scan attack from Internet Protocol
> (IP) address 80.176.209.174. A well-known port is any port in the range of
> 1-2048. For more information about this event, see ISA Server Help.
>
> What steps can I take if any, is this a genuine intrusion attempt or
> possibly a virus infected system somewhere ?
>
> Thanks in Advance
>
> Gary
>
>


.



Relevant Pages

  • Re: The Trackers First Review Response
    ... > the hacker books written and noticed none approached it from a "basic ... configure not only AV software but the integral firewall. ... was the destination IP address and port? ... How does this benefit a basic user who has no reason to know? ...
    (microsoft.public.security.virus)
  • Re: Microsoft SBS 2000 Internet Permissions Problem
    ... The web site logon page is access via HTTPS port 85: ... If Microsoft Internet Explorer is configured to reference a server that is ... ISA Server 2000 Standard Edition, ...
    (microsoft.public.windows.server.sbs)
  • Re: Computer Misuse Act
    ... Hackers build, crackers break ... and has no legitimate purpose. ... A port scan could be legitimate in a couple of cases - if the ... who has been called a hacker. ...
    (uk.legal)
  • port forwarding (rerouting) with isa server.
    ... I have a question about port forwarding with isa server. ... external nic connected to the router and one internal nic ...
    (microsoft.public.isa)
  • Re: Trying to understand this behavior, Ports in IIS
    ... That tells me the ISA server was accepting the connections. ... assign port 8080. ... In the border router and in the PIX firewall (both devices are "in front of" ...
    (microsoft.public.inetserver.iis.security)