Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Firewall warning

Thread Tools
 
Search this Thread
 
Old Apr 10, 2010 | 10:33 PM
  #1  
Adrian F's Avatar
Adrian F
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 2,122
Likes: 0
Default Firewall warning

I got a firewall warning off of my Norton package should i be worried does this mean i have some thing on my PC or that i am being targeted (i am taking my ex-employee to tribunal) how did they know the name of my PC? i am only recently swapped to a new mobile broadband connection so how did it find my? or is it just a random attack?

Risk name Eleonore Toolkit activity

Attacking computer onlinesoft.name (91.201.64.8, 80)

Attacking URL. Onlinsoft.name/3dd/index.php

destination address (Adrian PC 92**

source address 91.201.64.8 (91.201.64.8)

Traffic description TCP, www-http

Application path \device\hardiskvolume2\program files\internetexplorer\Iexplore.exe

status blocked
Reply
Old Apr 11, 2010 | 10:02 AM
  #2  
Kieran_Burns's Avatar
Kieran_Burns
Scooby Regular
iTrader: (1)
 
Joined: Jul 2004
Posts: 10,208
Likes: 0
From: There on the stair
Default

So you were browsing a dodgy Polish web-site and got sniffed?

Be careful where you look next time
Reply
Old Apr 11, 2010 | 11:41 AM
  #3  
Adrian F's Avatar
Adrian F
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 2,122
Likes: 0
Default

No on that laptop and dongle not been anywhere more risky than Scoobynet, pistonheads, LFTO (walking forum) big brand name email web access pages that sort of thing, that is why i was concerned.

If i had been on a dodgy site i would have expected the firewall to show a problem and asked how to clean my PC!
Reply
Old Apr 11, 2010 | 01:03 PM
  #4  
Markus's Avatar
Markus
Scooby Regular
25 Year Member
 
Joined: Mar 1999
Posts: 25,080
Likes: 0
From: The Great White North
Default

a whois lookup on that IP shows the following:

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 91.0.0.0 - 91.255.255.255
CIDR: 91.0.0.0/8
NetName: 91-RIPE
NetHandle: NET-91-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS2.LACNIC.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 2005-06-30
Updated: 2009-05-18

# ARIN WHOIS database, last updated 2010-04-10 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at https://www.arin.net/whois_tou.html
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '91.201.64.0 - 91.201.67.255'

inetnum: 91.201.64.0 - 91.201.67.255
netname: Donekoserv
descr: DonEkoService Ltd
country: RU
org: ORG-DS41-RIPE
admin-c: MNV32-RIPE
tech-c: MNV32-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-by: MNT-DONECO
mnt-by: MNT-DONECO
mnt-lower: RIPE-NCC-END-MNT
mnt-routes: MHOST-MNT
mnt-routes: MNT-PIN
mnt-domains: MHOST-MNT
source: RIPE # Filtered

organisation: ORG-DS41-RIPE
org-name: DonEko Service
org-type: OTHER
address: novocherkassk, ul stremyannaya d.6
e-mail: admin@pinspb.ru
mnt-ref: MNT-PIN
mnt-by: MNT-PIN
source: RIPE # Filtered

person: Metluk Nikolay Valeryevich
address: korp. 1a 40 Slavy ave.,
address: St.-Petersburg, Russia
e-mail: nm@internet-spb.ru
phone: +7 812 4483863
fax-no: +7 901 3149449
nic-hdl: MNV32-RIPE
mnt-by: MNT-PIN
source: RIPE # Filtered

% Information related to '91.201.64.0/23as44050'

route: 91.201.64.0/23
descr: doneco 2 PIN
origin: as44050
mnt-by: MNT-PIN
source: RIPE # Filtered
Reply
Old Apr 11, 2010 | 01:03 PM
  #5  
Markus's Avatar
Markus
Scooby Regular
25 Year Member
 
Joined: Mar 1999
Posts: 25,080
Likes: 0
From: The Great White North
Default

a whois lookup on that IP shows the following:

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 91.0.0.0 - 91.255.255.255
CIDR: 91.0.0.0/8
NetName: 91-RIPE
NetHandle: NET-91-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS2.LACNIC.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 2005-06-30
Updated: 2009-05-18

# ARIN WHOIS database, last updated 2010-04-10 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at https://www.arin.net/whois_tou.html
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '91.201.64.0 - 91.201.67.255'

inetnum: 91.201.64.0 - 91.201.67.255
netname: Donekoserv
descr: DonEkoService Ltd
country: RU
org: ORG-DS41-RIPE
admin-c: MNV32-RIPE
tech-c: MNV32-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-by: MNT-DONECO
mnt-by: MNT-DONECO
mnt-lower: RIPE-NCC-END-MNT
mnt-routes: MHOST-MNT
mnt-routes: MNT-PIN
mnt-domains: MHOST-MNT
source: RIPE # Filtered

organisation: ORG-DS41-RIPE
org-name: DonEko Service
org-type: OTHER
address: novocherkassk, ul stremyannaya d.6
e-mail: admin@pinspb.ru
mnt-ref: MNT-PIN
mnt-by: MNT-PIN
source: RIPE # Filtered

person: Metluk Nikolay Valeryevich
address: korp. 1a 40 Slavy ave.,
address: St.-Petersburg, Russia
e-mail: nm@internet-spb.ru
phone: +7 812 4483863
fax-no: +7 901 3149449
nic-hdl: MNV32-RIPE
mnt-by: MNT-PIN
source: RIPE # Filtered

% Information related to '91.201.64.0/23as44050'

route: 91.201.64.0/23
descr: doneco 2 PIN
origin: as44050
mnt-by: MNT-PIN
source: RIPE # Filtered
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Frizzle-Dee
Essex Subaru Owners Club
13
Mar 9, 2019 07:35 PM
dpb
Non Scooby Related
14
Oct 3, 2015 10:37 AM
dantiel
General Technical
8
Sep 29, 2015 11:33 PM
fumbduck
ScoobyNet General
18
Sep 29, 2015 09:16 PM
TylerD529
Lighting and Other Electrical
5
Sep 20, 2015 12:10 PM




All times are GMT +1. The time now is 09:13 AM.