|
|
Subject:
port scanned, need to trace
Category: Computers Asked by: icmp-ga List Price: $10.00 |
Posted:
04 Aug 2002 11:48 PDT
Expires: 03 Sep 2002 11:48 PDT Question ID: 50517 |
I just bought a new (used) laptop from a friend - now I am getting port scans from the user that XP Pro is registered to. I want to contact them to find out what the deal is. I have my zone alarm pro log files to help you out. | |
| |
| |
| |
|
|
Subject:
Re: port scanned, need to trace
Answered By: ufphoenix-ga on 04 Aug 2002 15:05 PDT Rated: |
That IP currently resolves to CPE000393860552.cpe.net.cable.rogers.com. If you want to keep from seeing these alerts, you need to install a firewall and block the specific portscans from this address. You may be able to convince the rogers company to assign this particular problem user a static IP so that you do not have to block the entire ISP, but in situations like these, especially if it is a mere port scan and not a DoS attack, they may or may not be cooperative. I personally recomment SyGate firewall although there are many many options on firewalls, including ones that are not quite as complex; these may be more suited in your situation since you are solely concerned with a portscan and blocking a specific person. These firewalls can be configured to 1) block the specific port and/or 2) block the ISP (or if you can get the ISP to be cooperative, the static IP). As for finding out who the person actually is, Rogers is correct in saying that since no DoS attack is being performed, they have no legal (or moral) obligation to tell you who owns the specific account; in fact, they would be violating that person's privacy. Hope this helps. http://www.sygate.com http://www.tinysoftware (tiny firewall) Here's an interesting article on how firewalls work: http://www.pcworld.com/hereshow/article/0,aid,17012,00.asp | |
|
icmp-ga rated this answer: |
|
Subject:
Re: port scanned, need to trace
From: secret901-ga on 04 Aug 2002 14:07 PDT |
How did you know that the person performing the port scans were the person who registered your computer? |
Subject:
Re: port scanned, need to trace
From: lunatic_high_ff-ga on 18 Sep 2002 14:11 PDT |
The best way that I have found to trace IPs on the internet and get more information about the offending computer is to go to www.arin.net and from there, click on the Tools link, then click on the text-only whois link and type in the IP address and click on the submit query button. This will tell you who the IP is registered to. To (possibly) find more information about the IP at the time the scanning occurred, you can (if on a Windows computer) open a command prompt and try a ping using the -a switch on the IP address. The command string would look like ping -a 10.128.1.1 or whatever the IP address would be at the time. You can also use the tracert command on a windows computer to follow the path that would be needed to connect your computer to the offending computer. On a *NIX computer (UNIX, Linux, etc), the ping command works the same, but you use traceroute instead of tracert to trace it. There are applications that can be found on the internet that will actually map out the approximate location of the source IP as well, but it has been a long time since I've looked for them. Also, depending on your internet connection, the port scanning would most likely be from some script kiddie using some application to try and find insecure computers that they can drop "zombie" applications on the computer. |
If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you. |
Search Google Answers for |
Google Home - Answers FAQ - Terms of Service - Privacy Policy |