I was browsing through my home router's device logs and I'm seeing port scans every 2-3 minutes from a whole slew of different IP addresses. I've counted at least 30-something separate domains. My router has a built-in firewall, but is being port scanned this much typical?[Edited on January 1, 2009 at 2:49 PM. Reason : ]
1/1/2009 2:48:08 PM
Nah- definitely not the norm. Mind sharing a snippet of the logs?
1/1/2009 3:25:36 PM
^also, do you have a static IP on your WAN interface?
1/1/2009 3:29:16 PM
Whos your ISP?If you can, disconnect it overnight. That often will fix stuff like that. Otherwise itll probably continue for a while.
1/1/2009 5:32:00 PM
russian or chinese hackers
1/1/2009 5:40:49 PM
I re-installed my router and it stopped for a few hours but started back up again. I'm using dynamic addressing for my WAN and my ISP is earthlink/twc. Here's my recent device log:
1/2/2009 3:04:23 AM
okay, I just ssh'd into a remote computer and just tried port scanning my own IP with nmap and I'm getting nothing... so can I assume my firewall is blocking outside access to my ports?
1/2/2009 3:19:21 AM
Sure, you can assume anything you like. :pMost likely, the scans are coming from zombies on a botnet that the owner has sic'd on a known block of dynamic IPs owned by a major ISP.
1/2/2009 4:26:41 AM
thats why i block all of asia and eastern europe
1/2/2009 7:22:16 AM
My guess that it isn't really anything to worry too much about. Looking at the logs, the router doesn't really provide you with any information you can actually use in order to determine what is going on. Take for example the logs for 74.125.67.118:
1/4/2009 10:36:35 AM