Port 80 Scan Galore!

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
DIDS
Posts: 947
Joined: Sat Apr 15, 2000 12:00 am
Location: Syracuse, New York

Port 80 Scan Galore!

Post by DIDS »

I am getting hit like crazy with Port 80 scans. Most likely due to the Code Red Worm. They are all primarily on RoadRunner. Anyone esle getting nailed alot by these scans?
User avatar
W_I_Z_K_I_D
Regular Member
Posts: 363
Joined: Sun Jun 10, 2001 9:33 am
Location: !!!Your Computer-You Just Dont Know It YeT!!!

Post by W_I_Z_K_I_D »

Yo listen Dids
i aint got no port 80 scans latelly but yeah your right...probbaly got somethin to do with code red..
Kepp my ears and eyes open bro....You might whanto check with Greed and see what port 80 is and what its used for...he has an interesting port list.....could be uselfull
lAyTa ;)
!!!What Man Can Make
Man Can Brake!!! :irate:

Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM

** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner


Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
User avatar
greEd
Posts: 807
Joined: Wed May 09, 2001 12:00 am
Location: Maryland

Post by greEd »

port 80 is http
"I'm doing a (free) operating system (just a hobby, won't be big and professional...) for AT clones... It's not portable and it probably [won't ever] support anything other than AT hard disks, as thats all I have :-(." --Posted on Usenet August 1991 by Linus Trovalds
http://www.computerglitch.net
curiosity builds security | dd if=/dev/zero of=/dev/hda bs=512 count=100
EOF
Logan 5

Post by Logan 5 »

DIDS,

Yes I am getting hit on port 80 big time. Using ZoneLog Analyser
and it is showing them from all over the place.

Jim
User avatar
Dakota
Posts: 5694
Joined: Tue Oct 03, 2000 12:00 am
Location: Vancouver, Wa

Post by Dakota »

Nothing's getting past my router to ZAPro, but my modem lights (data and activity) are blinking just like I'm downloading a file. Been doing that all day today, but no data is coming through, and nothing to my computers except what's supposed to come through. Speed is also unaffected as I get 500—1,000-plus KB/ps at HappyPuppy. I called ATT and they have no idea what's going on either, but they have been getting a bunch of complaints on it today and they are trying to find out what's up.
We Remember...
9|11
40 miles SW of Mt. St. Helens
User avatar
fredra
Advanced Member
Posts: 847
Joined: Mon Mar 20, 2000 12:00 am
Location: Nepean, On, Canada

Post by fredra »

Same here with the Port 80 scans....my router is not letting them through, but my logs are filling up and speed is adversely affected....
And it is constant...OMG...it NEVER stops....
I will have to just shut the sucker down and go watch TV
PEACE!!!!!
A man with a watch knows what time it is. A man with two watches is never sure.
User avatar
Dakota
Posts: 5694
Joined: Tue Oct 03, 2000 12:00 am
Location: Vancouver, Wa

Post by Dakota »

Weird. My speed is not effected at all as I said above...
We Remember...
9|11
40 miles SW of Mt. St. Helens
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

I think this is the full scale attack! I've got one sub 7 hit and the entire log is filled with port 80 hits. I can't clear the alert fast enough!
MrTRiX
Regular Member
Posts: 104
Joined: Fri Jun 29, 2001 2:47 pm
Location: Saskatoon, SK

Post by MrTRiX »

I am trying to make a TPF rule so I can see them all?

Is it Port 80 on TCP Incoming? And should I set it to watch Local port 80 or remote port 80?
I think I've done enough conventions to know how to spell Melllvar.
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

port 80 TCP incoming and I believe local. might try it both ways though.
Zporttech
Advanced Member
Posts: 688
Joined: Tue Jul 04, 2000 12:00 am
Location: Indiana

Post by Zporttech »

My port 80 has also been under attack. About 200 hits yesterday (8/4).

Using @Home in Indiana.............
User avatar
Zuma
Posts: 601
Joined: Sat Aug 04, 2001 12:00 pm
Location: Vancouver WA

Post by Zuma »

My modem is still going nuts, but nothing is getting past the router to Tiny. Unlike BlueJetta tho my speed is horrible (40KBs at HappyPuppy) ACK!
User avatar
BadEditor
Regular Member
Posts: 315
Joined: Sat Dec 18, 1999 12:00 am
Location: Lost...

Post by BadEditor »

I'm getting 'probed' alot too :rolleyes:

Starting saturday around 11am is when I started to Notice it....

My Zonealarm is Logging around 350 port scans from Various IP addresses.....

Called Tech and They know about it....
User avatar
boobless
Member
Posts: 39
Joined: Wed Dec 27, 2000 12:00 am

Post by boobless »

same here....got close to 500 port 80 scans since yesterday. am on cox@home in RI.

@guard's not letting em through tho. most of them seem to be comming from up north...in or near canada.
( * ) ( . )
User avatar
chimdogger
Posts: 2785
Joined: Fri Jan 26, 2001 12:00 pm

Same Story different modem in Florida on RR

Post by chimdogger »

The Chimdogger checking in....
My modem is possesed. Get me a preist! Port 80 scans up the buTT. Couple sub7 scans for good measure. Dont know what the deal is but I am considering a cable router. What could they be scanning for on port 80. Everybodys computer is wide open on port 80 but what are they hitting it for???? If there is an exploit for port 80 then things are going to get real interesting...

Later on,

Chimdogger out
User avatar
Juggernaut
Senior Member
Posts: 1645
Joined: Fri Aug 11, 2000 12:00 am
Location: Parts Unknown

Post by Juggernaut »

Originally posted by boobless
most of them seem to be comming from up north...in or near canada.
It's all a plan for us Canucks to take over ;)
Image
It can't rain all the time...
cyberskye
Senior Member
Posts: 4717
Joined: Wed Jan 10, 2001 12:00 am
Location: DC

Post by cyberskye »

Code Red proliferates by scanning for other unpatched IIS servers. Most often these servers would be listening on tcp port 80 (http)...

I received over 500 requests yesterday - I'm on comcast@home, alexandria VA.

Most of them are coming from other hosts on the @home network all over canada and some from new england.

Speeds are down from 2400-3200 Down to about 1000. And I thought @home said they were going to start blocking inbound requests on port 80 across their network...

Skye
anything is possible - nothing is free

:wth:
Blisster wrote:It *would* be brokeback bay if I in fact went and hung out with Skye and co (did I mention he is teh hotness?)
:wth:
User avatar
fredra
Advanced Member
Posts: 847
Joined: Mon Mar 20, 2000 12:00 am
Location: Nepean, On, Canada

Post by fredra »

From Canada eh
We are taking over...watch out...lol
PEACE!!!!
A man with a watch knows what time it is. A man with two watches is never sure.
Post Reply