Gnutella Forums  

Go Back   Gnutella Forums > Gnutella News and Gnutelliums Forums > General Gnutella / Gnutella Network Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Gnutella / Gnutella Network Discussion For general discussion about Gnutella and the Gnutella network.
For discussion about a specific Gnutella client program, please post in one of the client forums above.


Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old April 28th, 2001
Novicius
 
Join Date: April 27th, 2001
Location: Philomath, OR, USA
Posts: 4
kencx is flying high
Post UDP 137 port probes

Ever since I set up my firewall settings to catch log UDP port opens, I've been getting a lot of UDP 137 port opens when running my Gnutella client (limewire). About every 15 minutes a new one comes in from a different source.

I'm not a TCP expert, 137 is listed as netbios nameserver service in /etc/services. Only two possiblilites come to mind. Either some gnutella client is trying to use this service for some unknown but legitimate purpose, or someone as learned that the gnutella network protocol provides a rich source of IP addresses that can be probed for security holes. The second possibility seems to be the more probable of the two.
  #2 (permalink)  
Old April 28th, 2001
Novicius
 
Join Date: April 27th, 2001
Posts: 2
Snapzz is flying high
Post

Intresting, I dont know what it means but it makes ya wonder....

Heres an example from another thing I have noticed. An ip was nocking at my firewall hours after I was off line but it would increment port numbers each time. Say for example 63.227.9.161:11661 then 63.227.9.161:11662 etc....

I have no idea why..

  #3 (permalink)  
Old April 29th, 2001
charrea6
Guest
 
Posts: n/a
Post

Sounds like u were being port scanned, its commonly used by hackers to see if u have got any open ports that they can use to get into your system, but seeing as u had a firewall up and running I wouldn't worry too much.
On the UDP port front, just a note TCP and UDP are 2 separate protocols under the connection protocol of IP, so becarefull when looking up the port numbers as u can have 2 different (although unlikely) types of service running on TCP and UDP
  #4 (permalink)  
Old April 29th, 2001
Novicius
 
Join Date: April 27th, 2001
Location: Philomath, OR, USA
Posts: 4
kencx is flying high
Post

Got the following response from one of the ISP's that I reported this to. I guess I can stop worrying about it.

Thank you for your contact.

This is not a probe... A connection from source port 137 to destination
port 137 using the UDP protocol is result of windows networking
misconfiguration.
  #5 (permalink)  
Old April 29th, 2001
Apprentice
 
Join Date: April 29th, 2001
Posts: 8
A. Coward is flying high
Exclamation

Excuse the poor gramar and spelling I really am dyslexic.

Well even ISPs run portscans looking for "illegal" servers, and port scanning isn't illegal.
I think your ISP is full of it and trying to alay your fears.
What are the originating IP addresses? Many kiddies run portscans. I am on a cable modem network in a very small town of less than 10,000, I get on average 20 port scans a week. This is mostly L337 Haxor wannabees right here in town. Given the right script tools they can and will hose up your system ask anyone who has been rooted. Usually they are using class 3 or non-routable ip address trying here to sneak into a poorly secured boxes and home networks. The set up of the cable network here allows for these supposed internal or non-routable ips to be used. Your computer should be set to reject all outside class3 ip and outside non-routable addresses as a default, and not running netbios or open windoz shares at all if you don't need them.
Your ISP dosen't give a hoot for a residental accounts security so you have to do it on your own. Some don't give a flying leap for the commercial customers security. You need to learn it and protect your self. If a endloser like me can learn it anyone can. All most ISP care about is the check you send them every month.
  #6 (permalink)  
Old May 4th, 2001
Abraxas
Guest
 
Posts: n/a
Lightbulb

this is a windooze box,trying to ask you about your netbios shares. Could be misconfig, could be whatever.

I, anyway, never understood thse guys who connect a windooze box directly to the net... nor people using gnutella on windows... aren't you afraid?
  #7 (permalink)  
Old May 4th, 2001
highschoolslut
Guest
 
Posts: n/a
Lightbulb

Wow, and I thought the people at hotline were dorks.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
when a port is busy like say 6346 what is another good port # to use for my other Butterfly9 LimeWire+WireShare Tips and Tricks 0 January 31st, 2007 11:47 AM
Listen on Port 80 - Port not available Cooper73 Download/Upload Problems 1 September 20th, 2005 07:06 PM
Port numbers for firewall port forwarding? Frozen_Charlotte Connection Problems 1 January 8th, 2003 09:53 AM
Could not find a port to use for incoming connections. Please specify a port from the Unregistered Connection Problems 1 September 1st, 2001 12:17 PM
Firewall TCP Port probes miklos Connection Problems 1 June 25th, 2001 08:50 AM


All times are GMT -7. The time now is 07:41 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.