Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Understanding - Internet Access Control messages

Status
Not open for further replies.

vbportal

Technical User
Nov 7, 2002
53
HR
Hi,
I just installed Norton Internet Security and being afraid of any hacker attacks, I have enabled everything.
I keep getting a lot of the following messages:
A remote computer is attempting to access your computer:
Protocol: TCP (inbound)
Remote address: 217.235.237.106:4833
Local address 172.178.194.39:4662

Under personal firewall
I also get some specific info/stats about
recent intrusion attempts: 112
recent attempted attackers: 1
most frequent attacker:147.208.171.140


I would like to know:
(a)How can one find out what the remote addresess/attacker refer to - who is it/is it dangerous or not (eg is it the url I am accessing/my ISP or)
(b)What must one have turned on (at the moment I'm clicking on "OK" for blocking each of the remote addresses
(and there are alot of them ;) )

Is there some other software/freeware which does a more detailed tracking/analysis/info about attacks ?

Thanks,
Vjeko
 
Hi Vjeko! a) Port 4662 sounds like Kazaa or some other P2P soft. People are searching for nodes to connect to, or if you are on a dial-up connection, the guy using the IP address before you got it, was using P2P and the sharing network hasn't noted his disappearance yet.

For port lists just enter "well-known ports" or "TCP port list" into Google and you will find lots of sites.

b) You should begin with blocking everything and then open ports needed for the stuff you want to do i. e. mail, Web etc.

You could install a freeware intrusion detection system like snort or a sniffer to get more details on packets.

Hope, that helps
Ralf
 
Ralf is correct.

In particular pay attention to part b! Close everything, except what you know you need open. And then open only as needed.

If you're not sure you need a port open, keep it closed until you find something that doesn't work, then find the port it needs and open it.

Keep checking your logs!

=============
Mens et Manus
=============
 
I have the same problem, I think. I looked at morpheus then deleted. I suspected this was the problem. However, I just switched from dialup to cable and the problem followed. How do I get these things to stop coming every 5 sec. Literally.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top