palomuuri ilmoitti skannauksesta...

Discussion in 'Virukset ja haittaohjelmat' started by prommi, Feb 6, 2007.

  1. prommi

    prommi Guest

    Sygaten palomuuri ilmoitti tällaisesta...Mitä meinaa???tai siis ymmärrän mutta kuka scannaa?!? onko tullut vastaan?

    Somebody is scanning your computer.
    Your computer's TCP ports:
    1433, 5900, 1025, and 135 have been scanned from **.***.***.***
     
  2. prommi

    prommi Guest

    kyseessä on siis ripe.net...

    tuollaista sain irti palomuurista.

    % This is the RIPE Whois query server #2.
    % The objects are in RPSL format.
    %
    % Note: the default output of the RIPE Whois server
    % is changed. Your tools may need to be adjusted. See
    % http://www.ripe.net/db/news/abuse-proposal-20050331.html
    % for more details.
    %
    % Rights restricted by copyright.
    % See http://www.ripe.net/db/copyright.html

    % Note: This output has been filtered.
    % To receive output for a database update, use the "-B" flag

    % Information related to '88.192.0.0 - 88.192.255.255'

    inetnum: 88.192.0.0 - 88.192.255.255
    netname: SONERA-FINLAND-BBNET
    descr: Broadband access pool
    descr: TeliaSonera Finland Oyj
    country: FI
    admin-c: MP5226-RIPE
    tech-c: SIH3-RIPE
    status: ASSIGNED PA
    remarks: ---------------------------------------------------------
    remarks: Please send abuse and spam notifications to abuse@inet.fi
    remarks: ---------------------------------------------------------
    mnt-by: DATANET-NOC
    source: RIPE # Filtered

    role: Sonera Inet Hostmaster
    address: TeliaSonera Finland
    address: Vetu/SMO/Access/Hostmaster
    address: PL 106
    address: 00051 SONERA
    phone: +358 2040 1
    fax-no: +358 2040 69100
    remarks: trouble: Please send abuse and spam notifications to abuse@inet.fi
    remarks: trouble: General information: http://www.sonera.com/
    admin-c: KE351-RIPE
    tech-c: HE740-RIPE
    abuse-mailbox: abuse@inet.fi
    nic-hdl: SIH3-RIPE
    mnt-by: DATANET-NOC
    source: RIPE # Filtered

    person: Marko Perala
    address: PL 710
    address: 00051 SONERA
    address: Finland
    phone: +358 20401
    nic-hdl: MP5226-RIPE
    mnt-by: DATANET-NOC
    source: RIPE # Filtered

    % Information related to '88.192.0.0/14AS5515'

    route: 88.192.0.0/14
    descr: DN-088192-BLOCK
    origin: AS5515
    remarks: ---------------------------------------------------------
    remarks: Please send abuse and spam notifications to abuse@inet.fi
    remarks: ---------------------------------------------------------
    mnt-by: DATANET-NOC
    source: RIPE # Filtered


     
  3. kimez

    kimez Member

    Joined:
    Nov 28, 2006
    Messages:
    22
    Likes Received:
    0
    Trophy Points:
    11
    Samanlainen porttien skannaus ilmoitus tuli mullekin juuri. Sygaten palomuuri käytössä.

    Eka samasta ip:stä: Portscan; severity minor; protocol tcp
    30 sek. myöhemmin: Active response; severity major; protocol none

    Pitäskö tehdä jotain, vai onko normaalia?
    log:

    Somebody is scanning your computer.
    Your computer's TCP ports:
    1433, 135, 5900, and 139 have been scanned from 91.152.251.181..


    % This is the RIPE Whois query server #2.
    % The objects are in RPSL format.
    %
    % Note: the default output of the RIPE Whois server
    % is changed. Your tools may need to be adjusted. See
    % http://www.ripe.net/db/news/abuse-proposal-20050331.html
    % for more details.
    %
    % Rights restricted by copyright.
    % See http://www.ripe.net/db/copyright.html

    % Note: This output has been filtered.
    % To receive output for a database update, use the "-B" flag

    % Information related to '91.152.0.0 - 91.152.255.255'

    inetnum: 91.152.0.0 - 91.152.255.255
    netname: ELISA-ADSL
    descr: Elisa Oyj
    country: FI
    admin-c: KH-RIPE
    tech-c: KH-RIPE
    status: ASSIGNED PA
    mnt-by: ELISA-MNT
    source: RIPE # Filtered

    role: Elisa Hostmaster
    address: Elisa Oyj
    admin-c: KH-RIPE
    tech-c: KH-RIPE
    nic-hdl: KH-RIPE
    abuse-mailbox: abuse@elisa.fi
    mnt-by: ELISA-MNT
    source: RIPE # Filtered

    % Information related to '91.152.0.0/13AS719'

    route: 91.152.0.0/13
    descr: Elisa Oyj
    origin: AS719
    mnt-by: ELISA-MNT
    source: RIPE # Filtered

    Niin, ja huomasin että samoja portteja nuuskitaan mullakin.
    1433, 5900 ja 135 . Mitähän portteja nää on ?
     
    Last edited: Feb 16, 2007
  4. Java9

    Java9 Guest

    just joo. Mun kone on täss jo täyss explorer.exe virus virheilmoituksia!
     
  5. kelari

    kelari Regular member

    Joined:
    Jul 26, 2006
    Messages:
    627
    Likes Received:
    0
    Trophy Points:
    26

Share This Page