Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

HELP! - Whats going one with my firewall log?

Thread Tools
 
Search this Thread
 
Old 22 June 2004, 10:30 AM
  #1  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default HELP! - Whats going one with my firewall log?

Just lately my browser has been refusing to open up new pages "page unavailble". My firewall log is showing ALOT of activity of ports 135 & 445. Maybe an attempt every 20secs or so.

The source and destination IP are very similar with only the last .???.??? being different, if i reconnect, its ok for a minute and then the same thing starts to happen. Is this my own computer making these requests?

The source DNS is from by own service provider everytime.

Any help greatly appreciated.

Boro.
Old 22 June 2004, 10:54 AM
  #2  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Boro
Just lately my browser has been refusing to open up new pages "page unavailble". My firewall log is showing ALOT of activity of ports 135 & 445. Maybe an attempt every 20secs or so.

The source and destination IP are very similar with only the last .???.??? being different, if i reconnect, its ok for a minute and then the same thing starts to happen. Is this my own computer making these requests?

The source DNS is from by own service provider everytime.

Any help greatly appreciated.

Boro.
13 attempts in 60 seconds, surely thats not normal internet traffic?
Old 22 June 2004, 05:23 PM
  #3  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

any ideas?
Old 22 June 2004, 06:57 PM
  #4  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Boro
any ideas?
See below hope this helps

Nick


TCP Port 135
Common Use
Microsoft Remote Procedure Call (RPC) service.

Inbound Scan
Currently inbound scans are likely the Nachi or MSBlast worms.

Outbound Scan
Outbound scans if occurring in volume should be considered an indication of a possible worm infection on the source computer and should be investigated.

TCP Port 445
Common Use
Microsoft-DS Service is used for resource sharing on Windows 2000, XP, 2003, and other samba based connections. This is the port that is used to connect file shares for example.

Inbound Traffic
Inbound scans are typically systems which are trying to connect to file shares that might be available on your system and hence these should be blocked. While most of this traffic is the result of worms or viruses which can use open file shares to propagate, they also can be the result of malicious users attempt to connect to your computer. Once connected they can download, upload or even delete or edit files on the connected file share. If you use open file shares (including sharing of printers, etc) on your local network (LAN), then you should be using a firewall such that your local file shares are not accessible from the internet. Connecting to open file shares is likely the easiest and most common hack on the internet and yet one of the most effective for malicious activities like identity theft or installing RATs (Remote Access Trojans) to take control of systems remotely for example.

Lately TCP Port 445 has become the target of LSASS exploiting worms like Sasser and Korgo.

Outbound Traffic
Outbound scans if occurring in volume should be considered an indication of a possible worm infection on the source computer and should be investigated. If there are systems to which you remotely connect to, then those systems should be marked as trusted IPs within Link Logger such that future authorized events will be logged as normal traffic.
Old 23 June 2004, 01:23 PM
  #5  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks Nick, im still gettin these by the bucket load by the minute.

Even after reconnecting which gives me a different ip address, within seconds they start again. Am i being targeted or could this just be general trojan/virus activity?
Old 23 June 2004, 02:41 PM
  #6  
Suresh
Scooby Regular
 
Suresh's Avatar
 
Join Date: Jan 2000
Posts: 4,622
Received 2 Likes on 1 Post
Default

Boro, the message is that your computer is infected with a worm/virus.
Do you have an uptodate virus scanner?

Suresh
Old 23 June 2004, 02:58 PM
  #7  
DJ Dunk
Moderator
Support Scoobynet!
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Default

Almost certainly a virus. Check your hosts file for loopbacks. Could be Agobot, it loops back loads of antivirus websites to localhost so they can't be accessed.
Old 23 June 2004, 06:13 PM
  #8  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Host files for loopbacks?

Ive ran two virus scans and picked up nothing.
Old 23 June 2004, 08:21 PM
  #9  
DJ Dunk
Moderator
Support Scoobynet!
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Default

Do a search on your C drive for a file called "hosts" and just check that there are no entires like . . . .

www.sophos.com 127.0.0.0.1
Old 23 June 2004, 09:00 PM
  #10  
R1916v
Scooby Regular
 
R1916v's Avatar
 
Join Date: May 2002
Posts: 1,002
Likes: 0
Received 0 Likes on 0 Posts
Default

Or its just the internet worms doing the rounds, hitting your firewall which is stopping them and logging it??

It even says so on the post by Nicks.

The viri target the rpc port, and I'm sure there are other viri (these might do it as well) that also target file share ports.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
dantiel
General Technical
8
29 September 2015 11:33 PM
ossett2k2
Engine Management and ECU Remapping
15
23 September 2015 09:11 AM
ossett2k2
Engine Management and ECU Remapping
12
17 September 2015 08:47 PM
Welloilbeefhooked
Engine Management and ECU Remapping
5
12 September 2015 05:32 PM



Quick Reply: HELP! - Whats going one with my firewall log?



All times are GMT +1. The time now is 01:27 AM.