Opera port scan !
-
loup001 last edited by loup001
Hi guys, user on stable version 51.0.2830.40 ( arch linux ) getting port scan from opera server.
03/09/2018 10:11:05 Vecna Scan 77.111.246.5, 8000->> xx.xx.xx.xxx, 54980 (from WAN Inbound)
03/09/2018 10:11:05 TCP FIN Scan 77.111.246.5, 8000->> 192.168.2.2, 54958 (from WAN Inbound)
03/09/2018 10:11:05 TCP FIN Scan 77.111.246.5, 8000->> xx.xx.xx.xxx, 55024 (from WAN Inbound)
03/09/2018 10:01:24 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52746 (from WAN Inbound)
03/09/2018 10:01:23 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52526 (from WAN Inbound)
03/09/2018 10:01:23 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52778 (from WAN Inbound)
03/09/2018 10:01:22 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52672 (from WAN Inbound)
03/09/2018 10:01:22 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52668 (from WAN Inbound)
03/09/2018 10:01:21 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52710 (from WAN Inbound)
03/09/2018 10:01:21 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52764 (from WAN Inbound)
03/09/2018 10:01:20 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52672 (from WAN Inbound)
03/09/2018 10:01:20 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52684 (from WAN Inbound)
03/09/2018 09:51:47 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52086 (from WAN Inbound)
03/09/2018 09:51:46 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52054 (from WAN Inbound)
03/09/2018 09:51:45 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52086 (from WAN Inbound)
03/09/2018 09:51:45 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 52026 (from WAN Inbound)
03/09/2018 09:51:45 TCP FIN Scan 77.111.246.6, 8000->> 192.168.2.2, 52086 (from WAN Inbound)
03/09/2018 09:51:44 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 51952 (from WAN Inbound)
03/09/2018 09:51:44 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 51974 (from WAN Inbound)
03/09/2018 09:51:43 Vecna Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 51814 (from WAN Inbound)
03/09/2018 09:51:43 TCP FIN Scan 77.111.246.6, 8000->> xx.xx.xx.xxx, 51938 (from WAN Inbound)
03/09/2018 09:18:32 TCP FIN Scan 192.168.2.2, 51372->> 77.111.246.6, 8000 (from WAN OutboundIt append since a couple of days when surfing to msn.com site.
The address 77.111.246.6 is owned by aes opera.
If user reset vpn ( on/off the vpn flag ) then that pc is sending a tcp scan
03/09/2018 20:18:14 TCP FIN Scan 192.168.2.2, 47340->> 77.111.246.18, 8000 (from WAN Outbound)
03/09/2018 20:18:14 TCP FIN Scan 192.168.2.2, 58232->> 77.111.246.5, 8000 (from WAN Outbound)
03/09/2018 20:18:14 TCP FIN Scan 192.168.2.2, 40480->> 77.111.246.16, 8000 (from WAN Outbound)
03/09/2018 20:18:14 TCP FIN Scan 192.168.2.2, 49732->> 77.111.246.14, 8000 (from WAN Outbound)
03/09/2018 20:18:14 TCP FIN Scan 192.168.2.2, 56710->> 77.111.246.6, 8000 (from WAN Outbound)Is this normal ?
From another pc running opera-developer 53.0.2880.0, i do not have such behavior (alarms on router firewall)
Thank's for your time
-
A Former User last edited by A Former User
How can I check for these kind of logs on my system?
I am insterested in it because here opera causes serious lag to the other systems on the network when opening some pages.Opera stable on debian testing x64.
-
loup001 last edited by
@jimunderscorep
Those logs are from my router/network firewall.
You simply need to log in as administrator and if equiped/program, check appropriate logs. In my case it's a combine log all events.
Check with your router internet site for instructions.