tracking and tracing

This is a discussion on tracking and tracing within the Linux Security forums, part of the System Security and Security Related category; Hi, I have a question. On the network is there a way to find out that your system is beeing ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-30-2003
Peter Le
 
Posts: n/a
Default tracking and tracing

Hi,

I have a question. On the network is there a way
to find out that your system is beeing scan by someone,
and which port is beeing scan?

Thanks,

PL

Reply With Quote
  #2 (permalink)  
Old 10-30-2003
Maxim Belushkin
 
Posts: n/a
Default Re: tracking and tracing

There are two possible ways.
1. Search for "scan detection software" on any search engine.
2. Run your firewall logging all incoming SYN connections. Then, when,
in the log file, you see a certain IP address poking at various ports
(usually in order from lowest to highest, but not necessarily every
port, might probe just the more common ones), you'll know it's a scan.
If you make it log to a FIFO buffer, you could come up with a "scan
detection" piece of code yourself, too :)

Overall, I preder the second method, since it gives you an idea of
what a "scan" is actually reflected in - most are quite simple to
detect by eye from logs :)

- Time -

Peter Le wrote:

> Hi,
>
> I have a question. On the network is there a way
> to find out that your system is beeing scan by someone,
> and which port is beeing scan?
>
> Thanks,
>
> PL


--
Max Belushkin
Reply With Quote
  #3 (permalink)  
Old 10-30-2003
Volker Birk
 
Posts: n/a
Default Re: tracking and tracing

Peter Le <peter.t.le@philips.com> wrote:
> On the network is there a way
> to find out that your system is beeing scan by someone,
> and which port is beeing scan?


Of course. You're receiving packets, such scans are active.

VB.
--
X-Pie Software GmbH
Postfach 1540, 88334 Bad Waldsee
Phone +49-7524-996806 Fax +49-7524-996807
mailto:vb@x-pie.de http://www.x-pie.de
Reply With Quote
  #4 (permalink)  
Old 10-30-2003
Peter Le
 
Posts: n/a
Default Re: tracking and tracing

Thanks,

PL

Maxim Belushkin wrote:

> There are two possible ways.
> 1. Search for "scan detection software" on any search engine.
> 2. Run your firewall logging all incoming SYN connections. Then, when,
> in the log file, you see a certain IP address poking at various ports
> (usually in order from lowest to highest, but not necessarily every
> port, might probe just the more common ones), you'll know it's a scan.
> If you make it log to a FIFO buffer, you could come up with a "scan
> detection" piece of code yourself, too :)
>
> Overall, I preder the second method, since it gives you an idea of
> what a "scan" is actually reflected in - most are quite simple to
> detect by eye from logs :)
>
> - Time -
>
> Peter Le wrote:
>
>> Hi,
>>
>> I have a question. On the network is there a way
>> to find out that your system is beeing scan by someone,
>> and which port is beeing scan?
>>
>> Thanks,
>>
>> PL

>


Reply With Quote
  #5 (permalink)  
Old 11-02-2003
€®ik
 
Posts: n/a
Default Re: tracking and tracing

On Thu, 30 Oct 2003 08:52:29 -0800, the right honourable Peter Le
<peter.t.le@philips.com> wrote:

>Hi,
>
>I have a question. On the network is there a way
>to find out that your system is beeing scan by someone,
>and which port is beeing scan?
>
>Thanks,
>
>PL



have a look at SNORT: www.snort.org

frgr
Erik
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:08 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0