PDA

View Full Version : Firewall logs


Watto
01-06-2005, 06:31 PM
I had these event logs emailed to me by my firewall/router can anyone explain them for me ?

2005-05-31 16:50:46 - FIN Scan - Source:193.108.48.9,61883,WAN - Destination:144.137.81.146,6346,LAN

2005-05-31 16:53:17 - FIN Scan - Source:193.108.48.9,62415,WAN - Destination:144.137.81.146,6346,LAN

2005-05-31 17:00:14 - FIN Scan - Source:193.108.48.9,56449,WAN - Destination:144.137.81.146,6346,LAN

2005-05-31 17:33:58 - FIN Scan - Source:193.108.48.9,58803,WAN - Destination:144.137.81.146,6346,LAN


So I reset my firewall/router so that I would obtain a new IP and then i got this the next morning

2005-06-01 07:19:07 - FIN Scan - Source:193.108.48.9,59247,WAN - Destination:144.137.81.146,6346,LAN


My firewall/router is a Netgear FWG114P

Thanks

EDIT 1: It would a pear that resseting my router did not obtain a new IP as hoped.
EDIT 2: Port 6346 is the port i use for Shareaza and is the only external port I have open

ViLLaN
01-06-2005, 06:40 PM
I think it unlikely your being scanned.. More likely just a false positive from the Shareaza traffic.

Watto
01-06-2005, 06:47 PM
Thats good to hear.

Is there anything else i can do to protect myself from this sort of thing ?

ViLLaN
01-06-2005, 10:11 PM
I dont think you have anything to worry about. Its not unusual for some firewalls to pick up certain normal P2P traffic as attacks or scans.. You get alot of connections, from alot of hosts, with lots of different source ports.. It can look suss.

Dont worry about it.. If you only have that port open, failing a vulnerability in Shareaza, there shouldn't be an issue.