cancel
Showing results for 
Search instead for 
Did you mean: 
1

Ask

2

Reply

3

Solution

Why did a UDP port scan get through THG3000 hub?

tonygibbs16
4: Newbie

Hello,

I have another router with a firewall connected to a THG3000 Vodafone hub.

My additional firewall detected a UDP port scan attack from an IP address on the Internet.

Network_scanning_attack_via_Vodafone_router_231109.JPG

The THG3000 hub says that the firewall is turned on.

How was this UDP port scan able to get in?

Kind regards Tony 

35 REPLIES 35

Good idea @Cynric 

I did a ShieldsUp scan yesterday and it did not show that UPnP was enabled.

It also didn't show that port 41797 was open.

Kind regards Tony 

Cynric
16: Advanced member
16: Advanced member

@tonygibbs16  There's also https://canyouseeme.org that can try the port number for you.

Ripshod
16: Advanced member
16: Advanced member

The GRC uPnP scan is unreliable - doesn't detect any of my uPnP ports.

Port 41791 is an IANA reservered udp port.

Thanks @Ripshod 

Sounds like a good reason for the port to be blocked.

Kind regards Tony 

With an Implicit Deny All for all unsolicited traffic from the Internet unless explicitly permitted.

Kind regards Tony 

 

Ripshod
16: Advanced member
16: Advanced member

too late to editi but I meant 41797.

Is anyone runneing a bittorrent client?

Cynric
16: Advanced member
16: Advanced member

@tonygibbs16  Some other suggestions for users of the port https://www.speedguide.net/port.php?port=41797 

Hello @Ripshod 

Thanks for your reply.

No one is running a BitTorrent client here.

Kind regards Tony 

CrimsonLiar
16: Advanced member
16: Advanced member

Is the secondary router in a Double-NAT configuration?  This can cause the kind of Packet ID corruption that has the primary router forward packets to the secondary router where the originator info just points to that secondary router and no further!

Hello @CrimsonLiar 

No, there is not a double -NAT situation here. My Zyxel NBG7510 is acting as as router. The only NAT is in the THG3000.

Kind regards Tony