 |

04-07-2004, 04:51 PM
|
 |
Senior Member
|
|
Join Date: May 2002
Location: San Jose, CA
Posts: 191
|
|
Undetected portscan
Can anyone tell me why the following was not detected as a portscan? I happened to be looking at the packet filter livelog and saw it, but it never showed up in my portscan log.
The IP address 209.233.190.166 is a second IP address for my WAN port, masqued to an internal webserver (SSL only).
<font color="green"> 2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7149 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7150 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7155 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7156 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7157 DF PROTO=TCP SPT=3884 DPT=139 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7722 DF PROTO=TCP SPT=3862 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7723 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7724 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7747 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7749 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9741 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9742 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9743 DF PROTO=TCP SPT=3862 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9758 DF PROTO=TCP SPT=3884 DPT=139 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9759 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9760 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
</font>
TIA,
Dan
|

04-07-2004, 07:09 PM
|
|
Wizard
|
|
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
|
|
Re: Undetected portscan
do you have an IPS license?
|

04-07-2004, 08:43 PM
|
 |
Senior Member
|
|
Join Date: May 2002
Location: San Jose, CA
Posts: 191
|
|
Re: Undetected portscan
No, but IPSec isn't part of this. I have the professional version (up to 50 IPs) ASL license on this machine.
|

04-07-2004, 09:46 PM
|
|
Wizard
|
|
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
|
|
Re: Undetected portscan
well the portscanner function is wrapped into the ids/ips section of ASL5 which is enabled(as of right now) only by purchasing a seaprate ips/ids license.
|

04-08-2004, 11:47 PM
|
 |
Senior Member
|
|
Join Date: May 2002
Location: San Jose, CA
Posts: 191
|
|
Re: Undetected portscan
That's interesting. I'm on ASL 4, not 5, and in both versions 3 & 4 portscan detection <font color="red"> WAS </font> part of the basic license. . .the ips/ids license is something I've never heard of. Can you point me to some documentation?
|

04-09-2004, 12:19 AM
|
|
Wizard
|
|
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
|
|
Re: Undetected portscan
[ QUOTE ]
That's interesting. I'm on ASL 4, not 5, and in both versions 3 & 4 portscan detection <font color="red"> WAS </font> part of the basic license. . .the ips/ids license is something I've never heard of. Can you point me to some documentation?
[/ QUOTE ]
goto astaro.com and read the press release about v5..  As far as the portscanner not working in your v4 i have no idea on that one..
|

04-10-2004, 11:14 PM
|
|
Junior Member
|
|
Join Date: Apr 2004
Location: Auckland - New Zealand
Posts: 12
|
|
Re: Undetected portscan
It is disapointing to see that Portscan has been removed in ASL5. Intrusion detection is certainly a major feature, even for slaves "home users" who contributed so much in debugging and PROMOTING this product. I have sold so many ASL to clients that this is not funny..
I believe that if the original marketing idea was great, this is now turning unfair and frustrating. [img]/images/graemlins/confused.gif[/img]
|

04-12-2004, 05:06 PM
|
 |
Senior Member
|
|
Join Date: May 2002
Location: San Jose, CA
Posts: 191
|
|
Re: Undetected portscan
Just a follow-up bit of information; I would guess that the portscan I included above got overlooked because it was spaced out over time. . .5 ports scanned, 3-second pause, 5 more scanned, another 3-second pause, and then 6 more scanned. It would appear that the threshold for portscan detection in ASL doesn't include logic to detect scans that are done in this more leisurely manner.
By contrast, I scanned myself using the website at grc.com and got the PSD warning right away.
Either this, or the PSD doesn't work on secondary IP addresses on the same NIC; and since I can't get GRC to scan my alternate IP (and I don't have another portscanner) I can't prove with any certainty which of these two scenarios is correct. . .but I bet Astaro can. A little help, guys???
D
|

04-13-2004, 03:50 AM
|
|
Moderator
|
|
Join Date: Jul 2001
Location: southern California
Posts: 5,359
|
|
Re: Undetected portscan
Astaro 3.x doesn't seem to pickup a lot of scans I see...
We have Astaro protecting a Class C, and with Snort/ACID, I see a lot of scans for open SOCKS and Squid proxy servers, scanning 1 or 2 ports on each IP across our network.
Astaro's scanner seems to only detect multi-port scans.
You could d/l the source of the old PSD module from Astaro before, but I'm not sure where it is now.
Also, the 4.x PlusPack includes the kernel source.
Barry
|

04-13-2004, 04:02 AM
|
|
Wizard
|
|
Join Date: Jun 2003
Location: geocenter
Posts: 623
|
|
Re: Undetected portscan
Dan,
I think the scan wasn't fast enough to be detected:
<font class="small">Code:</font><hr /><pre>psd weight-threshold: 21 delay-threshold: 300 lo-ports-weight: 3 hi-ports-weight: 1</pre><hr />
If I am reading the rule for portscan detection right - this means ports below 1024 get a score of 3 and ports above 1. If the total score reaches 21 PSD would detect a scan but not if there are more than 300ms in between the single scan attempts.
There is a gap for exampbe between 09:45:15 and 09:45:18
Start calculating :-)
Greetings
cyclops
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 03:08 AM.
| |  |