local network port scanning

This forum is dedicated to basic help and support :

Ask here your questions about basic installation and usage of Mageia. For example you may post here all your questions about getting Mageia isos and installing it, configuring your printer, using your word processor etc.

Try to ask your questions in the right sub-forum with as much details as you can gather. the more precise the question will be, the more likely you are to get a useful answer

local network port scanning

Postby nw1456 » Dec 23rd, '12, 15:07

Hi,
My daughter has a laptop running Windows 7. Every time she comes home from Uni I start getting Port scanning warnings from the firewall, from her local ip address.
If I process the "attack" and blacklist that ip, that stops it. Problem is that it keeps recurring after a reboot.

Question: Is there a way to permanently block that ip?

Question: Why the bloody hell does this Win7 machine keep scanning ports on other machines on the network?
nw1456
 
Posts: 22
Joined: Jan 11th, '12, 13:02
Location: UK

Re: local network port scanning

Postby oj » Dec 23rd, '12, 17:38

Is the IP multicast perchance? (240.0.0.x or thereabouts?) If so, that's windows network resource discovery at work. The machines basically play "Marco-Polo" on the network, asking for any reply within a certain IP range where things like windows media center servers live.

The best thing to do is disable that discovery on the windows machine. It's not easy using the windows advanced firewall control. (too many details) Try a thuird party 'firewall' like zone alarm, which makes things more comprehensible.

If it's an IP in the range of the LAN, it's still probably some kind of service discovery. (eg printers) Check what port(s) it's calling on, to identify the service, then disable it on the windows machine.

The tool for this is wireshark. Install/run it (as root) and capture a minute or two of traffic, then look through for the IP/port combination (aka "socket") from the offending machine.
oj
 
Posts: 232
Joined: Aug 23rd, '12, 00:22

Re: local network port scanning

Postby nw1456 » Dec 23rd, '12, 18:13

ok, thanks for that. Have installed Wireshark and running it now. The offending laptop is off at the moment, but I'll grab it when it comes back on line, then I'll try and turn the service off. I don't do Windows so I'll give it a googling.

Cheers
nw1456
 
Posts: 22
Joined: Jan 11th, '12, 13:02
Location: UK

Re: local network port scanning

Postby djennings » Dec 24th, '12, 01:22

The easy solution is just to tun off port scan detection in Mageia so you do not see the alarms.
In MageiaControlCentre>Security>Firewall after clicking OK you are invited to disable Port scanning or the interactive notifications.
User avatar
djennings
 
Posts: 613
Joined: Jun 2nd, '11, 23:51
Location: Wokingham, UK

Re: local network port scanning

Postby nw1456 » Dec 24th, '12, 02:02

Ah! I did look in the firewall configuration but couldn't see any way to alter settings. I'm assuming if I turn off the interactive part it will work as normal and just not bother me with warnings. Yes?
nw1456
 
Posts: 22
Joined: Jan 11th, '12, 13:02
Location: UK

Re: local network port scanning

Postby djennings » Dec 24th, '12, 02:48

nw1456 wrote:Ah! I did look in the firewall configuration but couldn't see any way to alter settings. I'm assuming if I turn off the interactive part it will work as normal and just not bother me with warnings. Yes?


Yep.
You could even turn off the firewall altogether. The firewall in your router will do a perfectly good job of protecting you. This is not like Windows. So long as you are not running a telnet or ssh server remote attackers are not going to get in.
User avatar
djennings
 
Posts: 613
Joined: Jun 2nd, '11, 23:51
Location: Wokingham, UK

Re: local network port scanning

Postby mailedfist » Jan 14th, '13, 23:10

I would have said that too, except that I am now seeing about 10 scans a day reported coming from the other side of the router provided by a well-known cable ISP!
Mandrake->Mandriva->Mageia starting in 2003. I really dislike another well-known distro starting with U.
mailedfist
 
Posts: 102
Joined: Sep 11th, '11, 21:28


Return to Basic support

Who is online

Users browsing this forum: No registered users and 1 guest