Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | I'm under attack!

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

I'm under attack!
Reply
 
Thread Tools
Old 15-08-2003, 23:14   #1
Chris
Trollsplatter
Cable Forum Team
 
Chris's Avatar
 
Join Date: Jun 2003
Location: North of Watford
Services: Humane elimination of all common Internet pests
Posts: 36,930
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
I'm under attack!

All evening my firewall has been constantly repelling attempts to get at my poor Mac ... from when I switched on at about 7.45 until I restarted it just now. My internet has been uselessly slow.

I don't know too much about these things but I had a suspicion that if I rebooted and acquired myself a new IP address the problem might go away. So far, it seems to have worked.

Strange thing is, virtually all the attempts came from within the ntl network, if I'm reading my access log right (it's attached). Anyone have a clue what this is all about?
Chris is offline   Reply With Quote
Advertisement
Old 15-08-2003, 23:20   #2
Mick
Cable Forum Team
 
Mick's Avatar
 
Join Date: Jun 2003
Posts: 15,118
Mick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny star
Mick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny star
Who knows but could be MSblast related, it seems to have an hidden agenda, one thats going to be unleashed tonight at midnight when those still infected with the worm and connected to web, that will 'blast' (reason behind its name) data to the microsoft website in a bid to crash the system.
Mick is offline   Reply With Quote
Old 15-08-2003, 23:22   #3
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 47
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Port 135, likely to be msblast (aren't you glad you bought a mac?)
Xaccers is offline   Reply With Quote
Old 15-08-2003, 23:27   #4
Chris
Trollsplatter
Cable Forum Team
 
Chris's Avatar
 
Join Date: Jun 2003
Location: North of Watford
Services: Humane elimination of all common Internet pests
Posts: 36,930
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
Quote:
Originally posted by Xaccers
Port 135, likely to be msblast (aren't you glad you bought a mac?)
:p

I am indeed tres, tres smug ... but then Mac geeks usually are.
Chris is offline   Reply With Quote
Old 16-08-2003, 00:23   #5
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 47
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Yeah, must be good to be so insignificant no one bothers with you
mumble mumble can't right mouse click mumble mumble
Xaccers is offline   Reply With Quote
Old 16-08-2003, 00:49   #6
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
One comment about the mac....

and it's on this page...
http://www.deadtroll.com/video/livehelldesk.html

right at the end
Lord Nikon is offline   Reply With Quote
Old 21-08-2003, 20:20   #7
Atomic22
Inactive
 
Atomic22's Avatar
 
Join Date: Jun 2003
Location: Orbiting Venus
Services: Very High Monthly Bills!
Posts: 1,052
Atomic22 is just really niceAtomic22 is just really niceAtomic22 is just really niceAtomic22 is just really niceAtomic22 is just really niceAtomic22 is just really nice
Send a message via ICQ to Atomic22 Send a message via AIM to Atomic22 Send a message via MSN to Atomic22 Send a message via Yahoo to Atomic22
some of us with older (but nicer) versions of windows (98se) are not affected by the blast virus and also have all 3 mouse keys to play with and so therefore we feel really smug
Atomic22 is offline   Reply With Quote
Old 21-08-2003, 20:52   #8
Z4pp4
Inactive
 
Join Date: Jun 2003
Posts: 22
Z4pp4 is an unknown quantity at this point
Towny

I am also getting battered on destination port 135, the connection is hopelessly slow, 99% from NTL customers, plus repetitive CyberKit 2.2 hits..
Its crap, the Microsoft product is totally venerable when connecting to the internet by itâ₠¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚¢s self and itâ₠¬ÃƒÂ¢Ã¢â‚¬Å¾Ã‚¢s clogging up network traffic.

Blame Kazaa users for clogging up the network †œmy backsideââ‚ ‚¬Ã‚

Ban micro$oft users from using up bandwidth with flaky software.

Fr4nk
Z4pp4 is offline   Reply With Quote
Old 21-08-2003, 21:19   #9
Z4pp4
Inactive
 
Join Date: Jun 2003
Posts: 22
Z4pp4 is an unknown quantity at this point
Angry

Infected by the MSBlast Internet Worm ... ISPs everywhere are blocking all port 135 traffic in an attempt to slow the worm's growth

Obviously not NTL

Fr4nk
Z4pp4 is offline   Reply With Quote
Old 21-08-2003, 21:29   #10
homealone
Guest
 
Posts: n/a
Quote:
Originally posted by Atomic22
some of us with older (but nicer) versions of windows (98se) are not affected by the blast virus and also have all 3 mouse keys to play with and so therefore we feel really smug
well we are a bit affected, because of all the extra traffic.

one persistent entry in my firewall log resolves as

youhavetheblasterworm.ntli.net

- and I am on 98se

- presumably this is the welchi worm.?

- anyone had sobig.f yet?
  Reply With Quote
Old 21-08-2003, 21:48   #11
Steve H
Inactive
 
Join Date: Jun 2003
Location: Stoke-On-Heaven
Age: 37
Services: Freeview, 512k Pipex.
Posts: 1,758
Steve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of Quads
Send a message via ICQ to Steve H Send a message via MSN to Steve H Send a message via Yahoo to Steve H
Well I reinstalled XP Pro For my mate tonight, and about 20 seconds after re-connecting to the internet , the Blast worm was on his computer... Although, It rebooted Once, then I went to Remove it, It'd already gone!, Me thinks the Anti Virus Virus was there somewhere :p
Steve H is offline   Reply With Quote
Old 21-08-2003, 22:05   #12
XFS03
Guest
 
Location: East London (ex-C&W)
Services: XL broadband ntl250 modem
Posts: n/a
Quote:
Originally posted by Steve_NTL
Well I reinstalled XP Pro For my mate tonight, and about 20 seconds after re-connecting to the internet , the Blast worm was on his computer...
Didn't you turn on XP's firewall before connecting to the internet?
  Reply With Quote
Old 21-08-2003, 22:31   #13
Steve H
Inactive
 
Join Date: Jun 2003
Location: Stoke-On-Heaven
Age: 37
Services: Freeview, 512k Pipex.
Posts: 1,758
Steve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of Quads
Send a message via ICQ to Steve H Send a message via MSN to Steve H Send a message via Yahoo to Steve H
No - Didnt even think about it.
Steve H is offline   Reply With Quote
Old 22-08-2003, 00:14   #14
kronas
Inactive
 
kronas's Avatar
 
Join Date: Jun 2003
Location: heckmondwike
Age: 38
Posts: 10,767
kronas is cast in bronzekronas is cast in bronzekronas is cast in bronzekronas is cast in bronze
kronas is cast in bronzekronas is cast in bronzekronas is cast in bronzekronas is cast in bronze
Quote:
Originally posted by Steve_NTL
No - Didnt even think about it.
lmfao big mistake

well you know what to do about it :p
kronas is offline   Reply With Quote
Old 22-08-2003, 06:33   #15
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Not knowing much about the mac, why not see if you can stealth port 135, the reason the worms try multiple times with you is that they get a reply on that port address, so they try to force their way in. If the port doesn't respond, they assume no machine and move on.

(3 port stages
Open - traffic is allowed through
Closed - Traffic is blocked and a reply is given saying the port is closed
Stealthed - Traffic is blocked and no acknowlegement is given

Stealthed is the best, as far as the attacking machine knows there is no computer on that IP address at all)
Lord Nikon is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:26.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.