Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Virgin Media Internet Service (https://www.cableforum.uk/board/forumdisplay.php?f=12)
-   -   I'm under attack! (https://www.cableforum.uk/board/showthread.php?t=1904)

Chris 16-08-2003 00:14

I'm under attack!
 
1 Attachment(s)
All evening my firewall has been constantly repelling attempts to get at my poor Mac ... from when I switched on at about 7.45 until I restarted it just now. My internet has been uselessly slow.

I don't know too much about these things but I had a suspicion that if I rebooted and acquired myself a new IP address the problem might go away. So far, it seems to have worked.

Strange thing is, virtually all the attempts came from within the ntl network, if I'm reading my access log right (it's attached). Anyone have a clue what this is all about?

Mick 16-08-2003 00:20

Who knows :shrug: but could be MSblast related, it seems to have an hidden agenda, one thats going to be unleashed tonight at midnight when those still infected with the worm and connected to web, that will 'blast' (reason behind its name) data to the microsoft website in a bid to crash the system.

Xaccers 16-08-2003 00:22

Port 135, likely to be msblast (aren't you glad you bought a mac?)

Chris 16-08-2003 00:27

Quote:

Originally posted by Xaccers
Port 135, likely to be msblast (aren't you glad you bought a mac?)
:D :D :D :p :D :D :D

I am indeed tres, tres smug ... but then Mac geeks usually are. ;)

Xaccers 16-08-2003 01:23

Yeah, must be good to be so insignificant no one bothers with you :D
mumble mumble can't right mouse click mumble mumble :D

Lord Nikon 16-08-2003 01:49

One comment about the mac....

and it's on this page...
http://www.deadtroll.com/video/livehelldesk.html

right at the end :)

Atomic22 21-08-2003 21:20

some of us with older (but nicer) versions of windows (98se) are not affected by the blast virus and also have all 3 mouse keys to play with and so therefore we feel really smug

Z4pp4 21-08-2003 21:52

Towny

I am also getting battered on destination port 135, the connection is hopelessly slow, 99% from NTL customers, plus repetitive CyberKit 2.2 hits..
Its crap, the Microsoft product is totally venerable when connecting to the internet by itâ₠¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚¢s self and itâ₠¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚¢s clogging up network traffic.

Blame Kazaa users for clogging up the network †œmy backsideââ‚ ‚¬Ã‚

Ban micro$oft users from using up bandwidth with flaky software.

Fr4nk

Z4pp4 21-08-2003 22:19

Infected by the MSBlast Internet Worm ... ISPs everywhere are blocking all port 135 traffic in an attempt to slow the worm's growth

Obviously not NTL

Fr4nk
:mad:

homealone 21-08-2003 22:29

Quote:

Originally posted by Atomic22
some of us with older (but nicer) versions of windows (98se) are not affected by the blast virus and also have all 3 mouse keys to play with and so therefore we feel really smug
well we are a bit affected, because of all the extra traffic.

one persistent entry in my firewall log resolves as

youhavetheblasterworm.ntli.net

- and I am on 98se:D

- presumably this is the welchi worm.?

- anyone had sobig.f yet?

Steve H 21-08-2003 22:48

Well I reinstalled XP Pro For my mate tonight, and about 20 seconds after re-connecting to the internet , the Blast worm was on his computer... Although, It rebooted Once, then I went to Remove it, It'd already gone!, Me thinks the Anti Virus Virus was there somewhere :p

XFS03 21-08-2003 23:05

Quote:

Originally posted by Steve_NTL
Well I reinstalled XP Pro For my mate tonight, and about 20 seconds after re-connecting to the internet , the Blast worm was on his computer...
Didn't you turn on XP's firewall before connecting to the internet?

Steve H 21-08-2003 23:31

No - Didnt even think about it.

kronas 22-08-2003 01:14

Quote:

Originally posted by Steve_NTL
No - Didnt even think about it.
lmfao big mistake :rofl: :rofl: :rofl:

well you know what to do about it :p

Lord Nikon 22-08-2003 07:33

Not knowing much about the mac, why not see if you can stealth port 135, the reason the worms try multiple times with you is that they get a reply on that port address, so they try to force their way in. If the port doesn't respond, they assume no machine and move on.

(3 port stages
Open - traffic is allowed through
Closed - Traffic is blocked and a reply is given saying the port is closed
Stealthed - Traffic is blocked and no acknowlegement is given

Stealthed is the best, as far as the attacking machine knows there is no computer on that IP address at all)


All times are GMT +1. The time now is 22:56.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are Cable Forum