# What is this guy hoping will happen? (computer)

**URL:** <https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032>\
**Category:** Factual Questions\
**Created:** [November 2, 2005, 3:57am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032 "2005-11-02T03:57:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![saoirse](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@saoirse](https://boards.straightdope.com/u/saoirse)\
**Post date:** [November 2, 2005, 3:57am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/1 "2005-11-02T03:57:09Z")

</div>

My firewall has been telling me that it has been denying access to another user who is trying to get in to my computer. This is nothing new; I get them all the time. What I have started noticing is that, every thirty minutes or so, I’ll get on one from the same IP address. This address is at least pinging my computer on average every thirty minutes (it’s not a regular interval), for hours on end.  
Why does this individual keep doing this? What does he think is going to happen?

---

<div class="post-metadata">

**Author:** ![Silentgoldfish](https://avatars.discourse-cdn.com/v4/letter/s/e36b37/32.png) [@Silentgoldfish](https://boards.straightdope.com/u/Silentgoldfish)\
**Post date:** [November 2, 2005, 4:20am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/2 "2005-11-02T04:20:34Z")

</div>

He’s probably port scanning. He’s not attacking your computer specifically, but trying a range of IP addresses. Your firewall can’t tell that it’s one of many so it doesn’t report that.

So it’s nothing personal, unless you’ve got an open port :).

---

<div class="post-metadata">

**Author:** ![Valgard](https://avatars.discourse-cdn.com/v4/letter/v/7feea3/32.png) [@Valgard](https://boards.straightdope.com/u/Valgard)\
**Post date:** [November 2, 2005, 4:34am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/3 "2005-11-02T04:34:18Z")

</div>

> [@Silentgoldfish](#):
>
> He’s probably port scanning. He’s not attacking your computer specifically, but trying a range of IP addresses. Your firewall can’t tell that it’s one of many so it doesn’t report that.
> 
> So it’s nothing personal, unless you’ve got an open port :).

And he might not even know that he’s doing it if his PC was compromised…

If you want to take action you could try tracking down the ISP that owns that address and send them log files to show them what’s going on.

---

<div class="post-metadata">

**Author:** ![saoirse](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@saoirse](https://boards.straightdope.com/u/saoirse)\
**Post date:** [November 2, 2005, 5:45am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/4 "2005-11-02T05:45:44Z")

</div>

> [@Valgard](#):
>
> And he might not even know that he’s doing it if his PC was compromised…
> 
> If you want to take action you could try tracking down the ISP that owns that address and send them log files to show them what’s going on.

It’s actually the same ISP as I have (sometimes it shows up on the report). I did realize the address might not have been the same as the user who was doing it.

I figured he was port scanning, but sometimes the hits come in so frequently that it seems like he’s just doing me. I might be part of a very small group of addresses he scans, though.

---

<div class="post-metadata">

**Author:** ![DougC](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@DougC](https://boards.straightdope.com/u/DougC)\
**Post date:** [November 2, 2005, 7:07am UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/5 "2005-11-02T07:07:11Z")

</div>

- 
  - 
    - If it appears to be from the same ISP, you can definitely drop them an email about it. Don’t be accusatory–as said, it could easily be an infected computer and the user is unaware. If it’s on the ISP’s system they will want to take care to inform the user, just to avoid the (probable) email or ddos trouble.  
~

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [November 2, 2005, 12:18pm UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/6 "2005-11-02T12:18:24Z")

</div>

> [@saoirse](#):
>
> … I figured he was port scanning, but sometimes the hits come in so frequently that it seems like he’s just doing me. I might be part of a very small group of addresses he scans, though.

A port scanning program running even on a DSL line with slow upload speed can hit between 15 & 100 ports per _second._ If the bad guy is just hitting a few typical ports, ie looking for the easy pickin’s, that translates to 1 to 10 different PCs scanned per second.

In an hour he can hit 3600 to 36,000 PCs. You’re almost certainly not being specificly targeted.

---

<div class="post-metadata">

**Author:** ![Harmonious\_Discord](https://avatars.discourse-cdn.com/v4/letter/h/74df32/32.png) [@Harmonious\_Discord](https://boards.straightdope.com/u/Harmonious_Discord)\
**Post date:** [November 2, 2005, 12:39pm UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/7 "2005-11-02T12:39:44Z")

</div>

Sometimes it is the provider doing it. You can’t tell until you ask why address x is polling you all the time. Be able to supply the time and date of the occurances too.

---

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [November 2, 2005, 4:34pm UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/8 "2005-11-02T16:34:10Z")

</div>

I noticed a huge jump in traffic one day, and did some packet sniffing. It turns out that the offending machine has the same IP address as one of the hops that always shows up whenever I do a tracert, in other words, it’s one of my ISP’s machine. It apparently is set up to do a lot of pings and arps. I’m assuming it does this so that it can keep track of who is where and what addresses are really being used so that it won’t end up with an IP collision when it assigns DHCP addresses. It’s kind of annoying, because I used to be able to tell just looking at the lights on my cable modem if someone was up to no good.

---

<div class="post-metadata">

**Author:** ![saoirse](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@saoirse](https://boards.straightdope.com/u/saoirse)\
**Post date:** [November 2, 2005, 5:35pm UTC](https://boards.straightdope.com/t/what-is-this-guy-hoping-will-happen-computer/329032/9 "2005-11-02T17:35:17Z")

</div>

> [@engineer\_comp\_geek](#):
>
> I used to be able to tell just looking at the lights on my cable modem if someone was up to no good.

I figured that would be possible, but I never knew hot to figure it out. I’ll send an e-mail ot frontier. It probably will turn out to be them. And I’ll resist the urge to ping back a little while longer.
