over 50K intrusion blocks in 1 day!!!

Shimmishim

Elite Member
Feb 19, 2001
7,504
0
76
Well...

I've never seen so many blocks before.

I updated to the newest version of zonealarm....

look how many intrusion blocks i've had in one day!!!!

here

50k in the picture and a total of 141682....

anyone know why?
 

Regs

Lifer
Aug 9, 2002
16,666
21
81
Does ZOneAlarm list the intrusions and what port they were trying to use?
 

Noid

Platinum Member
Sep 20, 2000
2,390
193
106
If your IP ends with ".2"

Someone might be trying to use your IP for DNS.
(I'm not kidding)

I had a speakeasy IP that had this problem.
I kept sending speakeasy logs.
Speakeasy kept contacting the source.
The source kept saying thier config was OK.

I finally asked Speakeasy for a new IP.
They agreed.

Or, Have you used a Bittorrent tool lately...?
Yout IP will end up on hundreds of computers worldwide, trying to use your computer as a D/L source.

 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Welcome to the internet. This may be overwhelming at first, but get over it. This is not abnormal. This is one of the reasons I hate personal firewalls, they show people that don't understand a metric that means nothing.
 

Shimmishim

Elite Member
Feb 19, 2001
7,504
0
76
the port that it blocks is usually port 6346...

as for using bit torrent.. i have used it recently but stopped using it after finding about limewire...

but man, 50k in one day is the most i've ever seen...

on my laptop which has had zonealarm installed since july of 2003, it's had 20k in over 1 year and 3 months...

and i get 50k blocks in 1 day!

that just makes no sense to me at all!!!

my ip ends in .5 so.. hm...

up to 74919 now...

let's see if this happens after i install my new hard drives and reinstall everything...

i did a virus scan recently and saw that i have one :(

but i use a program callled startup cpl to check to see if anything is running in the background and nothing shows up that's unusual...

 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
I've seen a few thousand in 2 seconds before. 50k in a day is _nothing_. Welcome to the internet. It's normal. ;)
 
Jan 31, 2002
40,819
2
0
Originally posted by: n0cmonkey
I've seen a few thousand in 2 seconds before. 50k in a day is _nothing_. Welcome to the internet. It's normal. ;)

Wonder if I still have those firewall logs from my Nimda/Blaster admin experiences. :p

- M4H
 

Shimmishim

Elite Member
Feb 19, 2001
7,504
0
76
hahaha...

i've never seen it happen before... that's all... so it was strange seeing so many in one day...
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: MercenaryForHire
Originally posted by: n0cmonkey
I've seen a few thousand in 2 seconds before. 50k in a day is _nothing_. Welcome to the internet. It's normal. ;)

Wonder if I still have those firewall logs from my Nimda/Blaster admin experiences. :p

- M4H

A former coworker of mine created a tool to overload IDS systems. He accidentally let it run on the wrong network. :shocked:
 

Noid

Platinum Member
Sep 20, 2000
2,390
193
106
Limeware info

Google is your friend.

It's easy to use too :)

________- Edited__________

I had a smartass comment, that was in bad taste ... :D

I hope you learned a lesson :)

The intrustions will go away when the limeware system 'forgets' your IP.

In the meantime, your ping will be suckage, if you play games online
 

Shimmishim

Elite Member
Feb 19, 2001
7,504
0
76
thanks Noid!

that really helped a lot...

i just didn't think about googling it :)

good stuff though.... i guess it'll go down soon... :)
 

Noid

Platinum Member
Sep 20, 2000
2,390
193
106
I found that website name funny also.

It was one of the top on my search list too :D