• July 15, 2025, 02:47:54 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: 1 [2]

Author Topic: Hundreds of blocked incoming TCP connection request  (Read 27106 times)

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Hundreds of blocked incoming TCP connection request
« Reply #15 on: February 02, 2009, 07:14:03 AM »

Could be...the probed ports are kind of unexpected and there does not seem to be a clear pattern though.
Logged
DIR-655 H/W: A2 FW: 1.33

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Hundreds of blocked incoming TCP connection request
« Reply #16 on: February 02, 2009, 07:16:46 AM »

Had a quick look: Ecuador and Mexico...the narcos are coming  :)
Logged
DIR-655 H/W: A2 FW: 1.33

Lycan

  • Administrator
  • Level 15 Member
  • *
  • Posts: 5335
Re: Hundreds of blocked incoming TCP connection request
« Reply #17 on: February 02, 2009, 08:55:44 AM »

Those regions are known for Zombie/Black Hat traffic. I had a FTP server have a dictionary hack attempt on it as well as port scan from that region.

Logged

tentimes

  • Level 3 Member
  • ***
  • Posts: 127
Re: Hundreds of blocked incoming TCP connection request
« Reply #18 on: February 10, 2009, 12:21:10 PM »

I would advise you to run some additional tools other than your virus scanner:

- RUbotted, free from Trendmicro.com (install and keep running on all PC's, it will pick up very quickly any outgoing stuff that a virus scanner will sometimes NOT pickup. This might find something is running that is sending out information you are unaware of.

- Hijackthis (google it). Run it and look for any weird DLL's that are hapening at startup - check the DLL's/ I had a malware one in a startp DLL once that was never picked up by AVG or spybot

- A free rootkit checker (sophos do one I think) run it to check for stuff that, again, some virus scanners don't find

- Spybot, search and destroy (again free). Run at least once a week,

Also, if you are using norton or Mcafee, you may want to consider changing virus scanner.

In addition to known filesharing programs there are other downloaders that you may not realise are P2P. For example some MMORPG loaders (world of warcraft, lottro), video download service running kontiki which never shut down (sky, bbc etc video downloaders). All of these will have propagated your IP and someone other downloader might be running while you are asleep with cached IPs.

There is a lot more to security than your router ;)
Logged

Lycan

  • Administrator
  • Level 15 Member
  • *
  • Posts: 5335
Re: Hundreds of blocked incoming TCP connection request
« Reply #19 on: February 10, 2009, 12:25:14 PM »

Run a WAN side packet capture. All you need is a PC and a hub. Then you'll know everything

Logged
Pages: 1 [2]