Announcement

Collapse
No announcement yet.

Web Intrusions

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Web Intrusions

    I recently set up HomeSeer and got the web access working. Recent entries in my HS and Firewall logs have wondering if I should be concerned about web intrusions. For example, my HS log shows the following entries a few days ago:

    8/7/2004 11:20:14 PM~!~Info~!~ Got data but was not PUT or GET, from: 67.124.241.125 Data:
    8/8/2004 3:15:46 AM~!~Info~!~ Got data but was not PUT or GET, from: 62.43.113.62 Data: CONNECT login.icq.com:443 HTTP/1.0
    8/8/2004 7:09:58 AM~!~Info~!~ Got data but was not PUT or GET, from: 82.125.132.88 Data: CONNECT login.icq.com:443 HTTP/1.0

    For the same time period, my firewall log shows the following:

    2004/08/07 23:21:04 CDT low src=67.124.241.125 dst=67.35.233.73 ipprot=6 sport=4318 dport=1025 TCP Port Scan Detected, Packet Dropped 2004/08/08 21:05:34 CDT low src=67.208.165.29 dst=67.35.233.73 ipprot=6 sport=1354 dport=6129 TCP Port Scan Detected, Packet Dropped

    My layman's brain is interpreting this as:
    The firewall rejecting the first intrusion (8/7 PM), but missing the second two (8/8 AM),since there is nothing in the firewall log for 8/8 in the AM, and
    HomeSeer allowed the 2 early morning logins.

    Is this a correct interpretation? Should I be concerned?

    Thanks in avance for help.

    Joe

    #2
    Watch your port 443. I wouldn't leave it open unless you absolutely need it.
    But as far as the HS webserver, it is not prone to vulnerability, attacks and manipulation like MS IIS is.

    Bill


    ~Bill

    Comment


      #3
      http://ubb.homeseer.com/eve/ubb.x?a=...not+PUT+or+GET

      Comment

      Working...
      X