Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Firewall allowing connection

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > General IT Discussion
Register FAQ Community Calendar

Firewall allowing connection
Reply
 
Thread Tools
Old 12-08-2003, 19:16   #16
CuddlesTC
Inactive
 
CuddlesTC's Avatar
 
Join Date: Jun 2003
Location: Worthing
Posts: 21
CuddlesTC is an unknown quantity at this point
For the last couple of days my firewall has been reporting almost non-stop MSRPC TCP port probes, whereas this used to be a very rare type of probe - could this be for the same reason?
CuddlesTC is offline   Reply With Quote
Advertisement
Old 12-08-2003, 19:17   #17
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Any experts out there?
Taf is offline   Reply With Quote
Old 12-08-2003, 19:19   #18
homealone
Guest
 
Posts: n/a
seems to be a bit of a pattern


12/08/03 17:58:13 TCP 80.4.* 135 80.4.75.226 3440 Block
12/08/03 17:58:15 TCP 80.4.* 135 80.4.196.113 2499 Block
12/08/03 17:58:18 TCP 80.4.* 135 80.4.101.122 3838 Block
12/08/03 17:58:48 TCP 80.4.* 135 80.4.198.225 1142 Block
12/08/03 18:00:23 TCP 80.4.* 135 80.4.195.121 2698 Block
12/08/03 18:03:32 TCP 80.4.* 135 80.4.165.105 4328 Block
as you can see the scans are coming from the same IP segment as my addy. I wouldn't mind betting Altis's IP begins with 81.97.*

<edit> sorry Alan didn't see your post re 60/40 while I was typing
  Reply With Quote
Old 12-08-2003, 19:19   #19
Alan Waddington
Inactive
 
Alan Waddington's Avatar
 
Join Date: Jun 2003
Location: Farnham
Posts: 503
Alan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about them
Quote:
Originally posted by CuddlesTC
For the last couple of days my firewall has been reporting almost non-stop MSRPC TCP port probes, whereas this used to be a very rare type of probe - could this be for the same reason?
MSRPC = Microsoft Remote Procedure Call (which uses Port 135)

Thus yes, it is the msblast virus
Alan Waddington is offline   Reply With Quote
Old 12-08-2003, 19:20   #20
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
http://www.ntl-isp.ntl.com/lookup/default.asp

They've put a warning up....
Taf is offline   Reply With Quote
Old 12-08-2003, 19:22   #21
Alan Waddington
Inactive
 
Alan Waddington's Avatar
 
Join Date: Jun 2003
Location: Farnham
Posts: 503
Alan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about them
Note that there is another thread on here covering the same topic
http://www.nthellworld.co.uk/forum/s...&threadid=1791
Alan Waddington is offline   Reply With Quote
Old 12-08-2003, 19:23   #22
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Time for Admin to merge the two together?
Taf is offline   Reply With Quote
Old 12-08-2003, 20:02   #23
zoombini
Inactive
 
zoombini's Avatar
 
Join Date: Jun 2003
Location: England
Services: I no longer receive cable services, I blame the inept accounts dept for that.
Posts: 3,731
zoombini has reached the bronze age
zoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze agezoombini has reached the bronze age
Before it gets merged can I change it slightly and ask how I can tell if I have had anything past the firewall?

I am running linklogger and see plenty of attacks (green icons) at port 135 from NTL addresses.

But how do I know that they have been stopped or if they got past?

Etc.

Are there any dummies guides to knowing whats what with a firewall available?
zoombini is offline   Reply With Quote
Old 12-08-2003, 20:13   #24
Ramrod
Inactive
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 58
Services: Amazon Prime Video & Netflix. Deregistered from my TV licence.
Posts: 21,960
Ramrod has a golden aura
Ramrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden aura
Quote:
Originally posted by zoombini
Before it gets merged can I change it slightly and ask how I can tell if I have had anything past the firewall?

I am running linklogger and see plenty of attacks (green icons) at port 135 from NTL addresses.

But how do I know that they have been stopped or if they got past?

Etc.

Are there any dummies guides to knowing whats what with a firewall available?
Yes, i was wondering about that but I've run my anti-virus, had my ports checked and checked my registry as well. All clear, so my firewall must be doing it's job. *fingers crossed*
Ramrod is offline   Reply With Quote
Old 12-08-2003, 20:54   #25
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Just think of the iriots out there with no antiviral or firewall......
Taf is offline   Reply With Quote
Old 12-08-2003, 21:00   #26
Ramrod
Inactive
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 58
Services: Amazon Prime Video & Netflix. Deregistered from my TV licence.
Posts: 21,960
Ramrod has a golden aura
Ramrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden aura
Theres a thread on it on .com
Ramrod is offline   Reply With Quote
Old 12-08-2003, 21:54   #27
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 48
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Quote:
Originally posted by Taf
And of course NTL has no antiviral running on it's servers to protect it's users?
OI!
As someone who used to build the NT servers for NTL I take objection to that insinuation!
It's not NTL's servers that are infected, it's customers who aren't bright enough to get patched.
None of my servers were ever infected/hacked while I was in charge of them.
Xaccers is offline   Reply With Quote
Old 13-08-2003, 10:16   #28
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Nice to know... is it still that way?
Taf is offline   Reply With Quote
Old 13-08-2003, 10:37   #29
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
the 60/40 was on the symantec site

As it infects only windows OSs I doubt it would hit the NTL mailservers anyway.

It will however infect any Windows 2000, Windows NT, XP or Server 2003 system that has not yet been patched.
Lord Nikon is offline   Reply With Quote
Old 13-08-2003, 10:39   #30
Taf
cf.mega poster
 
Taf's Avatar
 
Join Date: Jun 2003
Location: Kairdiff-by-the-sea
Age: 69
Services: TVXL BBXL Superhub 2ac (wired) 1Tb Tivo
Posts: 10,367
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
Taf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny starTaf has a nice shiny star
I'm still getting small packets from other NTL addresses this morning, so lets hope they start patching their PCs soon....
Taf is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 00:32.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum