Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

I feel I'm under attack

Thread Tools
 
Search this Thread
 
Old 14 August 2003, 07:18 AM
  #1  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Post

Hi Everybody!

No its not just paranoia.

Since about 10 pm last night my PC has been under attack approximately every 15 seconds from external sources trying to push me a trojan.

Is anyone else experiencing this? Check your logs people.

I have a firewall thats bang up to date and all the latest windows patches but it still disturbs me. So instead of leaving my adsl on all the time, this morning I set it to disconnect when idle.

A question for the experts: What is the point in continually attacking my computer with the same trojan over and over? Surely if it fails once an attacker would give up and try something else? Am I missing the point?

Cheers
Old 14 August 2003, 08:01 AM
  #2  
Neil Smalley
Scooby Senior
 
Neil Smalley's Avatar
 
Join Date: Feb 2000
Posts: 8,204
Likes: 0
Received 0 Likes on 0 Posts
Post

It's probably an automated attack from the MSBLAST worm. So i suspect it'll still happen until the machine that's trying to infect you is cleaned.
Old 14 August 2003, 08:08 AM
  #3  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Post

I thought that might be the case.

However, the attack is coming from a never ending stream of different IP addresses - according to my logs.

Could this still be one machine doing it?

Is it possible to fake IP addresses?
Old 14 August 2003, 08:11 AM
  #4  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Yup, it's random. If it's all on port 135 is blaster.

Don't worry about it.
Old 14 August 2003, 08:38 AM
  #5  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Post

How do you tell which port it is?

Is that the number after the colon like:

123.321.123.321:135
Old 14 August 2003, 09:11 AM
  #6  
Dream Weaver
Scooby Regular
 
Dream Weaver's Avatar
 
Join Date: Feb 2000
Location: Lancashire
Posts: 9,844
Received 0 Likes on 0 Posts
Post

Yep
Old 14 August 2003, 09:15 AM
  #7  
Figment
Scooby Regular
 
Figment's Avatar
 
Join Date: Jul 2001
Location: deep inside your imagination
Posts: 24,057
Likes: 0
Received 0 Likes on 0 Posts
Post

How do I block specific ports? I have a Netgear router and can see where to set port forwarding, but not port blocking? Advice please?
Old 14 August 2003, 09:15 AM
  #8  
douglasb
Scooby Regular
 
douglasb's Avatar
 
Join Date: Jun 2003
Location: use the Marauder's Map to find out.
Posts: 2,041
Likes: 0
Received 0 Likes on 0 Posts
Post

I've had the same symptoms of loads of Trojan attacks from different IP addresses starting about 22.30 yesterday. However, they seem to be on port 27374. Is this the same thing?

Doug
Old 14 August 2003, 09:19 AM
  #9  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

If you're worried, use an intrusion detection system to analyse your logs...

Blocking ports depends on the router, but it should be possible.

Nick.

Old 14 August 2003, 09:32 AM
  #10  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

a quick measure for a home pc would be something like tiny personal firewall.
thats what i'm using (software based) and touch wood, seems to be fending off the nasties.....

good luck

BB
Old 14 August 2003, 09:34 AM
  #11  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Arrow

Dr Nick

Have you been picking up these attacks on the firewall logs? If so, then it sounds like it is doing its job. Download the patch from the Microsoft website (if you haven't already done so) and you should be OK.

Chris
Old 14 August 2003, 09:40 AM
  #12  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

Just a small question I am guessing even if you do have the patch the virus will still try to get past a firewall but it can do no damage????
Old 14 August 2003, 09:48 AM
  #13  
gregh
Scooby Regular
 
gregh's Avatar
 
Join Date: Dec 1999
Posts: 3,360
Likes: 0
Received 0 Likes on 0 Posts
Post

I don't seem to be getting any attacks in my firewall, despite the PC being on ADSL for 48hrs+

maybe my router is blocking it



Greg
Old 14 August 2003, 09:50 AM
  #14  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,853
Received 51 Likes on 34 Posts
Post

Does your Router have log files, if so take a look at the incomming traffic. Don't want you to feel left out
Old 14 August 2003, 10:52 AM
  #15  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Post

In reply to Chirs,

I got my info from the log files and AFAIK all software is bang up to date so I think I am safe..... for now.

However, as others have also now mentioned. What is the effect, if any, of this constant bombardment on my PC? if you know....

Cheers!

And thanks for all the other comments from others too...glad to know I'm not alone here.
Old 14 August 2003, 10:59 AM
  #16  
gregh
Scooby Regular
 
gregh's Avatar
 
Join Date: Dec 1999
Posts: 3,360
Likes: 0
Received 0 Likes on 0 Posts
Post

log files turned off on the router, the supplier forums says:

If it is in NAT mode then you will be fine.

Which I am, hence no issues for me!

Greg
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Abx
Subaru
22
09 January 2016 05:42 PM
Frizzle-Dee
Essex Subaru Owners Club
13
01 December 2015 09:37 AM
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
InTurbo
ScoobyNet General
21
30 September 2015 08:59 PM
STERNRITTER
ScoobyNet General
5
29 September 2015 09:05 PM



Quick Reply: I feel I'm under attack



All times are GMT +1. The time now is 06:45 PM.