Previous in Forum: Unwanted File   Next in Forum: IBM Goldies
Close
Close
Close
19 comments
Rating: Comments: Nested
Power-User

Join Date: Jun 2008
Location: Kentucky Lake
Posts: 390
Good Answers: 26

Why Do My Computer Ports Get Probed?

08/15/2012 10:19 AM

Are there any legitimate reasons for some domains to attempt to connect to ports on my computer?

All external connection attempts are blocked, but many of them apparently come from licit web sites.

I just wonder what they are trying accomplish, attempting to make these connections. I'd like to open the ports on a computer and let them connect, just to see what they're after. But although I can capture the connection and get basic information like # of packets and protocols, I can't tell what files on my computer are being accessed.

I don't consider these probes and scans a threat, since they are effectively blocked at the PC by the firewall, I'd just like to know of any software or other techniques that will allow me to understand what these probes and scans are trying to do.

Register to Reply
Pathfinder Tags: port firewall
Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.

Good Answers:

These comments received enough positive votes to make them "good answers".

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Guru
Hobbies - DIY Welding - Don't Know What Made The Old Title Attractive... Popular Science - Weaponology - New Member United States - US - Statue of Liberty - 60 Year Member

Join Date: Apr 2009
Location: Yellowstone Valley, in Big Sky Country
Posts: 7425
Good Answers: 295
#1

Re: Why do my computer ports get probed?

08/15/2012 10:24 AM

I believe these invasion attempts are made by CR4 members who have recently been banned from posting in the forum.

Those guys are desperate to continue commenting and will try anything!

__________________
Semper Ubi Sub Ubi
Register to Reply
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#2

Re: Why do my computer ports get probed?

08/15/2012 10:51 AM

There are people all over the world who spend every day trying to come up with ways to take your money, or just cause havoc.

Keep the firewalls up and the anti-virus protection current.

Register to Reply
12
Guru

Join Date: Mar 2007
Location: by the beach in Florida
Posts: 33392
Good Answers: 1817
#3

Re: Why do my computer ports get probed?

08/15/2012 11:30 AM

"...Like breeze blowing through the windows on a house, ports are just hardware locations used for passing data in and out. Like the breeze blowing in and out of the window, computers send information out (and receive data in) though these windows, or ports. (Not to confuse you but computers have internal ports (for connecting disk drives, monitors, keyboards, etc) as well as external ports (for connecting modems, printers, mouse devices, and other peripheral devices). But I'm not going to geek out about internal or external ports, let's just keep it simple here. How about an example?

  • I'm using port 80 (yes, I'm a web server computer) for sending this web page to your web browser. I'm do this by reading the web page off my disk then send it flying out of my port 80, over the merry Internet, all the way to your blazing fast computer. Your computer will receive it through a "receiving port" (which will not be port 80) and finally your web browser will read the HTML code and display it as the nice-looking web page you're reading right now.

But why port 80? Why do web servers use port 80? Nothing special about that number - people just got together and willy-nilly decided that port 80 would be the default port on which a web server would send out its content. Don't believe me? Ok, try this out: Go to your favorite web site, let's say http://www.t1shopper.com/ but instead of typing it in like you usually would, add a ":80" after the ".com" part, like this: http://www.t1shopper.com:80/. Magic! You'll get the same web page even if you specify the port number!

So what's the advantage of having port numbers like this? Well, with publicly-agreed on port numbering, entering a port number becomes optional! Yes, it's faster - we don't have to type our fingers silly entering the port number every time. Instead of http://www.t1shopper.com:80/ we can just type http://www.t1shopper.com/ and our computers know (because of the http prefix) that we are requesting a web page and so it uses port 80 by default, without us having to type it. Aren't computers fun!

Ok, let's really geek out! Port numbers have been divided into three ranges: the Well Known Ports (0 through 1023), the Registered Ports (1024 through 49151), and the Dynamic and/or Private Ports (these are very highest ports 49152 through 65535 and usually used for receiving data, as in our example above). And who keeps track of all these default port numbers, port lists and protocols? The Internet Assigned Numbers Authority. IANA not only coordinates this but also all the worldwide domain names and IP address assignments. They're busy. If you are a true geek, you'll enjoy the dry reading at RFC793 which gives the full technical description of ports.

Some viruses attack specific ports on your computer as part of their design such as the old SASSER virus which used TCP port 445. To test if you might be vulnerable to the SASSER virus, use the above port scan tool to scan port 445. If the portscan says it can get through port 445 on whatever firewall you hopefully have, and your computer's port 445 is also open/active, then you may be susceptible to the SASSER virus...."

http://www.t1shopper.com/tools/port-scan/

__________________
All living things seek to control their own destiny....this is the purpose of life
Register to Reply Good Answer (Score 12)
Power-User

Join Date: Jun 2008
Location: Kentucky Lake
Posts: 390
Good Answers: 26
#4
In reply to #3

Re: Why do my computer ports get probed?

08/15/2012 1:19 PM

Thanks SolarEagle, for the detailed and informative comment. This latest port probe was 37231 using UDP. Not sure why that particular port or what programs use it. It came from the dns server of a seemingly legit site but that doesn't mean it originated from there. I'm sure some port probes are malicious, but some I believe many are just gathering information. Marketing for example has no ethics that I am aware of, so they would not only feel compelled to get data any way they can, they would feel entitled to this information on people's personal computers (which aren't very personal anymore).

Either way I don't know much other than port, IP and host/domain names. I was wondering if there was a way to see what these attempted connections would do if they succeeded. My home's network topology it atypical to say the least. It's what happened when a stay- at-home dad had an enterprise-class server to play with. Blocking connections....let me count the ways. I just want to go a step further, out of curiosity. Don't worry, I'm not gonna hunt anybody down. Unless of course they're in marketing.

Register to Reply
Guru

Join Date: Mar 2007
Location: by the beach in Florida
Posts: 33392
Good Answers: 1817
#5
In reply to #4

Re: Why do my computer ports get probed?

08/15/2012 11:24 PM

Gee I guess they spooked....

"

Port 37231 is listed in the IANA group of Registered Ports however as of Tue Aug 14 2012 11:00:25 GMT-0400 (Eastern Daylight Time) it is either Reserved or Unassigned and has no services registered to it but you can double check at the official IANA list at the link here. To search for another port, just use the search box below.

"

__________________
All living things seek to control their own destiny....this is the purpose of life
Register to Reply
Guru

Join Date: Mar 2007
Location: by the beach in Florida
Posts: 33392
Good Answers: 1817
#7
In reply to #4

Re: Why do my computer ports get probed?

08/15/2012 11:54 PM

Well there are lots of software programs to monitor and record port activity, might even find something free....Found this Transmission control protocol from DARPA...

http://www.faqs.org/rfcs/rfc793.html

__________________
All living things seek to control their own destiny....this is the purpose of life
Register to Reply
Power-User

Join Date: Jun 2008
Location: Kentucky Lake
Posts: 390
Good Answers: 26
#9
In reply to #7

Re: Why do my computer ports get probed?

08/16/2012 12:52 AM

Wow, that historic! TCP from 1981. Thanks DARPA! Cool website, too.

Register to Reply
2
Guru

Join Date: Mar 2007
Location: by the beach in Florida
Posts: 33392
Good Answers: 1817
#10
In reply to #7

Re: Why do my computer ports get probed?

08/16/2012 12:54 AM

Here's a little blurb on UDP (user datagram protocol)...

http://condor.depaul.edu/jkristof/papers/udpscanning.pdf

__________________
All living things seek to control their own destiny....this is the purpose of life
Register to Reply Good Answer (Score 2)
Power-User

Join Date: Jun 2008
Location: Kentucky Lake
Posts: 390
Good Answers: 26
#12
In reply to #10

Re: Why do my computer ports get probed?

08/16/2012 1:06 AM

This looks good. Thanks!

Register to Reply
Power-User

Join Date: Jun 2009
Location: australia
Posts: 132
Good Answers: 14
#15
In reply to #10

Re: Why do my computer ports get probed?

08/16/2012 8:48 AM

there was a program i used years ago called traceroute , and zonealarm , between the two of them i could trace where hacking attempts were coming from

at the time i was getting up to 250 attempted hacks per day , most of them traced back to korea

the app was great , it showed which networks they were hacking through all the way back to their base

these days i want to use it to find out who has been hacking into my facebook page . why is it so ? at least facebook shows me who has logged in and from where , including logins from cities i have never been to ~

is there any better apps that do the above job these days ????

__________________
Jack of all trades . master of four or five
Register to Reply
2
Anonymous Poster #1
#19
In reply to #4

Re: Why do my computer ports get probed?

08/16/2012 11:12 AM

The reason you may see oddball port numbers, is that new port numbers (sockets) can be returned to the client's initial request on the well-known port. The new connections have port numbers which are, for all intents and purposes, random. (Except they are chosen to not conflict with pre-assigned or well-known ports)

Register to Reply Good Answer (Score 2)
Power-User
United States - Member - New Member Safety - Hazmat - New Member

Join Date: Apr 2012
Location: in the desert near ground zero
Posts: 207
Good Answers: 7
#11
In reply to #3

Re: Why do my computer ports get probed?

08/16/2012 1:01 AM

That port checking tool you mention was last updated more than three years ago, do you know of any more recent?

__________________
Dont squat with your spurs on, and always drink upstream from the herd.
Register to Reply
Guru

Join Date: Mar 2007
Location: by the beach in Florida
Posts: 33392
Good Answers: 1817
#13
In reply to #11

Re: Why do my computer ports get probed?

08/16/2012 1:08 AM
__________________
All living things seek to control their own destiny....this is the purpose of life
Register to Reply Score 1 for Good Answer
Guru

Join Date: Mar 2012
Posts: 2189
Good Answers: 84
#16
In reply to #3

Re: Why do my computer ports get probed?

08/16/2012 10:24 AM

Excellent post, SE!

Register to Reply
Guru

Join Date: Jun 2011
Location: Phnom Penh
Posts: 4019
Good Answers: 102
#6

Re: Why Do My Computer Ports Get Probed?

08/15/2012 11:34 PM

I reckon it's Aliens mate.

The whole port probing thing is their signature MO.

__________________
Difficulty is not an obstacle it is merely an attribute.
Register to Reply Score 1 for Off Topic
Power-User

Join Date: Jun 2008
Location: Kentucky Lake
Posts: 390
Good Answers: 26
#8
In reply to #6

Re: Why Do My Computer Ports Get Probed?

08/16/2012 12:11 AM

I thought they just took all the drywall jobs.

Register to Reply Score 1 for Off Topic
Guru
United States - Member - Member Engineering Fields - Electrical Engineering - Electrical Construction

Join Date: Apr 2010
Location: Mid Western USA - The Corn Belt
Posts: 1439
Good Answers: 58
#14
In reply to #8

Re: Why Do My Computer Ports Get Probed?

08/16/2012 8:22 AM

Alas..............landscaping jobs also

__________________
The first 5 days after a weekend are always the hardest................................
Register to Reply Off Topic (Score 5)
Guru

Join Date: Mar 2012
Posts: 2189
Good Answers: 84
#17
In reply to #8

Re: Why Do My Computer Ports Get Probed?

08/16/2012 10:26 AM

Oh noes!

Register to Reply Off Topic (Score 5)
Guru

Join Date: Mar 2012
Posts: 2189
Good Answers: 84
#18
In reply to #6

Re: Why Do My Computer Ports Get Probed?

08/16/2012 10:43 AM
Register to Reply
Register to Reply 19 comments

Good Answers:

These comments received enough positive votes to make them "good answers".

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Copy to Clipboard

Users who posted comments:

Barchetta (4); Doorman (1); europium (3); HeadsUp (1); KJK/USA (1); lyn (1); SolarEagle (5); spaceracer (1); Wal (1)

Previous in Forum: Unwanted File   Next in Forum: IBM Goldies

Advertisement