Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 11-12-2006, 09:59 AM   #1 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Router Message

Hi guys,

I wondered if you could help.

Basically im running a Belkin F5D7633-4 router and it seems to be fine. Runs fine and no disconnections etc.

I have 4 PCs networked (1 been an xbox 360) to it all via ethernet cable and its running fine. The wireless is switched on but is only used when my Dad needs it for his work laptop. The wireless has WPA-PSK security mode enabled, the SSID isnt broadcast a password is required and there is MAC address filtering also.

I basically turned my machiene on at approximately 16:12 and straight away logged onto my router settings via (192.168.2.1) on my browser. I checked the security logs just out of interest and came across this:

Quote:
Date/Time Severity Message
Nov 12 16:15:02 alert klogd: Intrusion -> IN=ppp_0_38_1 OUT= MAC= SRC=83.100.157.125 DST=192.168.2.1 LEN=48 TOS=0x00 PREC=0x20 TTL=121 ID=32401 DF PROTO=TCP SPT=3143 DPT=46273 WINDOW=16384 RES=0x00 SYN URGP=0
Could anyone please explain what this is? I noticed that the alert was made, just as i logged into the router setup page at 16:15. Ive tried to google people who have had similar messages and some believe it is just background traffic or it could be caused by a bittorrent port etc? I do believe that a PC was online at the time with bittorrent been used but i did turn it off earlier.

Can anyone help me please? I did a whois search on the "83.100.157.125" and it came back with "KarooADSL" who ive never heard of. My ISP is PlusNet if that helps.

Any help would be greatly appreciated,

Thanks. :)

Last edited by Danny_vtr; 11-12-2006 at 10:00 AM.
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 11-12-2006, 10:21 AM   #2 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Ive just had another:

Quote:
Nov 12 17:18:59 alert klogd: Intrusion -> IN=ppp_0_38_1 OUT= MAC= SRC=220.245.222.48 DST=192.168.2.1 LEN=48 TOS=0x00 PREC=0x20 TTL=112 ID=3731 DF PROTO=TCP SPT=1318 DPT=46273 WINDOW=65535 RES=0x00 SYN URGP=0
Completely different IP this time so it seems as though its just background noise.
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-12-2006, 01:44 PM   #3 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Ok bit of an update:

I updated the family firewall and the update must of closed off a few ports etc. Since then, touch wood ive not had anymore security logs.

All together before i updated i recieved 5 of them in the space of an hour. A couple were from Australia according to Whois and there were some from the UK. I take it this isnt an attack on me, just an instance of background noise due to the random locations from the IPs?

Thanks.
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-12-2006, 01:45 PM   #4 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Oh and im really sorry about the volume of posts.

Cheers.
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-12-2006, 02:16 PM   #5 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Further update!

It seems after i restarted the family PC and did another check that i was still getting these security messages (well i got 1). The IP seemed to match an american company, pretty blank on the details of the whois search.

Anyway, it soon clicked why i was getting these security alerts. It seems i had forgotten about the virtual server i setup for port forwarding on my utorrent. I had the TCP port 46273 open and on ALL of my logs this came up under "DPT=46273".

So, can anyone explain what happened? Is it because this port was open it therefore attracted background noise and this appeared as a security log? I just want to make sure that noone was purposely attacking me and these are just harmless alerts. I hope this will be the end of it now and it will return to normal.
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-12-2006, 03:14 PM   #6 (permalink)
Registered User
 
Join Date: Aug 2006
Posts: 12
OS: WinXP


Ive just been informed its only port scanning. Thanks. :)
Danny_vtr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:56 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85