CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Caught an intruder

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
tyciol

Sergeant
Sergeant


Joined: May 12, 2006
Posts: 78
Location: Canada

PostPosted: Tue Sep 05, 2006 7:50 pm    Post subject: Caught an intruder
Reply with quote

My Norton Firewall caught an intruder about a week ago, I kind of put it off, but now I really want to know who it was and confront them. I do have their IP, here's the report I got:

Quote:
Medium Risk Security Alert
Norton Personal Firewall has blocked an intrusion attempt.

Time: 3:17 PM
Date: 29/08/2006
Intrusion: Portscan.
Intruder: 24.153.23.66(domain(53))
Risk Level: Medium
Protocal: UDP.
Attacked IP: xxxxxxxxx
Attacked Port: 1858.


[Attacked IP edited by Site Mod]

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Sep 05, 2006 9:43 pm    Post subject:
Reply with quote

First, please remove your IP. Second, it is not an intruder, it was probably a routine ping from your cable provider's DNS server. That IP resolves for Rogers Cable, Inc., DNS servers. Most responses on port 53 are from a DNS inquiry. What possibly happened was during a routine DNS lookup, you had a brief interruption, and the DNS server was pinging back to see if you were still there. Nothing to worry about or report.

Now, if your ISP isn't Rogers ... well that's another matter.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
tyciol

Sergeant
Sergeant


Joined: May 12, 2006
Posts: 78
Location: Canada

PostPosted: Wed Sep 06, 2006 12:42 pm    Post subject:
Reply with quote

Oh okay, thanks, that had me worried because I'd never been hacked (that I know of) before. The weird thing is, this firewall came as part of the package from Rogers ISP :p

I can't find the button for editing post, it's not where it usually is in phpbb, so not sure how to remove IP.

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Sep 06, 2006 2:06 pm    Post subject:
Reply with quote

Right, for some reason I don't understand, posts in this forum can't be edited. I will notify a moderator and ask that they edit it for us.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
tyciol

Sergeant
Sergeant


Joined: May 12, 2006
Posts: 78
Location: Canada

PostPosted: Mon Sep 11, 2006 12:09 am    Post subject:
Reply with quote

Thanks, I'll try to remember to X that out if it happens later.

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
tyciol

Sergeant
Sergeant


Joined: May 12, 2006
Posts: 78
Location: Canada

PostPosted: Wed Sep 20, 2006 5:43 pm    Post subject:
Reply with quote

I got another one:

Quote:
Norton Personal Firewall - Security Alert - Medium Risk
Norton Personal Firewall has blocked an intrusion attempt.
Time: 1:37 PM
Date: 20/09/2006
Intrusion: Portscan.
Intruder: 85.255.115.6(domain(53)).
Risk Level: Medium
Protocal: UDP.
Attacked IP: (removed because told not to post any IP data, D or #)
Attacked Port: 2030.

It looks similar, but it's done at a different time of the day, from a different IP, and on a different port of mine than the last time. Shouldn't a routine server sweep be the same every time?

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
danielcg

Private
Private


Joined: Jan 02, 2006
Posts: 40


PostPosted: Thu Sep 21, 2006 11:51 pm    Post subject:
Reply with quote

Did you delete "Default Incoming DNS Rule" firewall rule in advanced tab? It sound that you deleted this critical rule in advanced tab.

Open Norton Control Panel, click on "Firewall" then click "Advanced" tab then click "System" button. Look for "Default Incoming DNS Rule" firewall rule in system rules. If not exist then you did deleted it. Please add "Default Incoming DNS" firewall rule and select "Permit" then select "Incoming to your computer" then select "UDP" then add "53" to entry. Make sure only UDP port 53 is listed. Then name the description (same as title I told you). Then select "Default and Home" then click "OK".

I know Norton Firewall will allow any remote IP to send UDP 53 but like me, you are using Rogers High Speed Internet Service, the router in the network do not allow UDP 53 from anyone except Rogers DNS server. It is external router, not your computer so you don't have to worry about port 53. Also, external router blocks port 135, 136 to 139 and 445. It also filter port 25, 53 and 123. You are responsible for all other ports. If you keep firewall rules at default, this firewall will block all other ports.

I am Rogers High Speed Internet subscriber just like you but never receive Intruder alert from Rogers Servers because I configured firewall rules correctly.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Thu Sep 21, 2006 11:58 pm    Post subject:
Reply with quote

Well, this one is not from Rogers. That IP comes back to Russia:


Quote:
85.255.115.6
85.255.115.6-xbox.dedi.inhoster.com
Host reachable, 125 ms. average

85.255.112.0 - 85.255.127.255

Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
Abuse notifications to: abuse@inhoster.com

Andrei Kislizin
OOO Inhoster,
ul.Antonova 5, Kiev,
03186, Ukraine
phone: +38 044 2404332

Fast Web Hosting Support
01110, Ukraine, Kiev, 20Á, Solomenskaya street. room 201.
UA
phone: +35 79 91 17 759

inhoster
Source: whois.ripe.ne


Don't bother complaining, it won't do you any good at all, and will let them know "you are home".


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
danielcg

Private
Private


Joined: Jan 02, 2006
Posts: 40


PostPosted: Fri Sep 22, 2006 3:44 am    Post subject:
Reply with quote

Oh! It may not be default firewall rule problem; you previously had malware installed or not! If you remove the malware, the attackers will try to access the malware (removed) in your machine and failed so they scan ports to find if there is any other malware(s).

I am lucky that I never to be attacked by the attackers who spoof source port number because I never had a malware or a virus before.

You can turn off "notification". Go to IPS screen and click "Advanced.." then search for Portscan then click Portscan and click "Properties" then untick "Notify or Alert me" but leave "blocking" on.

OR you can enable inbound firewall (Windows Firewall or wireless router or cable router) in addition to Norton Firewall.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Sep 22, 2006 9:37 pm    Post subject:
Reply with quote

danielcg wrote:
you can enable inbound firewall (Windows Firewall or wireless router or cable router) in addition to Norton Firewall.

This is not generally recommended. Multiple firewalls (and anti-virus, but generally not anti-malware) software often interferes in each others workings, and having two of them is often much worse than having only one.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
danielcg

Private
Private


Joined: Jan 02, 2006
Posts: 40


PostPosted: Sat Sep 23, 2006 2:00 am    Post subject:
Reply with quote

Inbound firewall is Windows Firewall builtin into Windows XP Service Pack 2.

NIS 2007 (not NIS 2006) will use inbound firewall feature (Windows XP firewall) as secondary firewall.

Yes, you are correct. Have more than one third-party firewall (exception of Windows Firewall) will cause conflicts with each other. Most third-party firewalls don't conflict with Windows Firewall OR Router's external firewall.

Anyway, I have old (Rogers ISP supplied) NIS 2006 installed and turned off Windows Firewall because I have LinkSys 802.1n wireless router that have built-in inbound (SPI) firewall so I don't need Windows Firewall. My Norton products don't have any issues with router's external firewall.

Back to top
View users profile Send private message
tyciol

Sergeant
Sergeant


Joined: May 12, 2006
Posts: 78
Location: Canada

PostPosted: Tue Oct 03, 2006 3:16 pm    Post subject:
Reply with quote

Ah, I'll keep the alerts on, but thank you for telling me that it's just some dude trying to access Malware and failing horribly either because of the wall or absence of malware to circumnavigate it.

I got a different one this time. It says high risk, and at the same time I got the warning, it also said that Norton deleted a virus on my system, so it's definately bad. Norton must be pretty good to be getting all these, as I assume they'd be top of the line viruses... perhaps I should work for them!

Quote:
Intrusion: HTTP MS Windows WMF Code Exec
Intruder: megacount.net(81.177.3.12)(http(80)).
Risk Level: High.
Protocol: TCP.
Attacked IP: localhost.
Attacked Port: 4101.
Note: didn't post Date/Time/My IP as they don't seem relevant.

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer