Notices
ScoobyNet General General Subaru Discussion
Sponsored by:
Sponsored by:

For the attention of an IT bod

Thread Tools
 
Search this Thread
 
Old 13 July 2001, 10:10 AM
  #1  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Question

Help,

I have a cable modem , and run zone alarm as a fire wall. I also have a net gear router to act as a gateway for other PCs (i.e. Childrens PC, laptop)

Until recently I have had no issues. Over the last few days I have had a slight problem. Zone alarm keeps stopping an out going connection to 207.91.106.5 port 1240, 1536, 1630 and 80 ? Does anyone know this IP address ?

Oh yes, and normally after the firewall stops the connection, explorer has an error and closes down ? This doesn't happen all the time, just sometimes!!

Cheers in advance, Phill

[This message has been edited by babber (edited 13 July 2001).]
Old 13 July 2001, 10:17 AM
  #2  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Post

Phill, what operating system are you using?

Old 13 July 2001, 10:32 AM
  #3  
Bugsie1
Scooby Newbie
 
Bugsie1's Avatar
 
Join Date: May 2000
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Post

Phil,

What's the source application of the outgoing packets? It should say when it alerts you.

FYI: That IP belongs to Verio.net - a web hosting firm in Atlanta, Georgia. You can try emailing them at: vipar@verio.net and ask about that IP.
The system at that IP is running Apache WebServer on UNIX.

I would hazard a guess that despite your security precautions you have a "Zombie" a kind of Trojan Horse on your PC. It's "calling home" to it's author. I would recommend you block all outgoing packets at the firewall to this IP address and tighten up your security somewhat.

What OS are you running? Try
Old 13 July 2001, 10:32 AM
  #4  
paulmon
Scooby Regular
 
paulmon's Avatar
 
Join Date: May 2000
Posts: 384
Received 2 Likes on 2 Posts
Wink

Have you tried turning everything off and then turning it back on again.
Old 13 July 2001, 10:46 AM
  #5  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

I think you'd be right to be wary of this one. Do let us know what the source application is for the request (Zone Alarm will show it in the logs, and alert you as to what is trying to do this).

The Web server there is running a blank index.htm page, which makes me suspect that it's used as a payload server - it stores nasty things that someone is trying to install on your machine.

Update your virus checker, keep zone alarm running...
Old 13 July 2001, 10:54 AM
  #6  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Interestingly none of those ports (except for 80) is even open on that machine, can you sniff the packets and see if it's attempting to access a certain URI? Your browser crashes because your OS of choice is amazingly unstable.

Steve.
Old 13 July 2001, 02:08 PM
  #7  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

All,

Currently running Win 98 SE.

Zonealarm has managed to block the out going packet every time, so I glad it's working as it should do.

Have disabled Netbios, file and printer sharing when I had the cable modem installed.

Have been using Norton anti virus with the latest updates, but shall try and get a newer version of updates tonight when I get in from work.

I have tried
Old 13 July 2001, 03:37 PM
  #8  
Avi
Scooby Regular
 
Avi's Avatar
 
Join Date: Apr 2001
Location: Manchester
Posts: 5,084
Likes: 0
Received 0 Likes on 0 Posts
Post

Going off the subject a little.. i also have a cable modem, but at the moment i have to have my gateway PC turned on all the time to be able to share the connection with my PC upstairs, how else can i do this, i can't just connect a hub onto the modem can i?. Somebody mentioned a router, would this work and is it an expensive option. I just want to be able to turn one of my pc's on not have to have both on!!.

Any help gratefully received

<I><B>Andy A</I></B>
Old 13 July 2001, 03:55 PM
  #9  
MorayMackenzie
Scooby Senior
 
MorayMackenzie's Avatar
 
Join Date: Jun 1999
Posts: 3,410
Likes: 0
Received 0 Likes on 0 Posts
Cool

Bugsie1,

Re: "What OS are you running? Try
Old 13 July 2001, 05:34 PM
  #10  
KF
Scooby Regular
 
KF's Avatar
 
Join Date: Feb 2000
Posts: 405
Likes: 0
Received 0 Likes on 0 Posts
Post

Or not let a muppet drive
Old 13 July 2001, 09:17 PM
  #11  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Post

Avi,
Who's your ISP ?

I would go for a router, they provide an easy option to connect to the internet with many PCs. The cable modem works very well with it. You get the router Nic Mac added to your accounts with ISP and that's it.

Minor dramas backing up the router, but once configured correctly, you never need to touch it again

I use the Netgear RT311 DSL / CM router, very nice, with a dual speed 8 port hub. The router cost around £100. A better solution for a cheap home network would be the RT314. Same as above, but with a internal four port hub (also dual speed). I think about £130.

Details at
Old 14 July 2001, 10:36 AM
  #12  
WillieF
Scooby Regular
 
WillieF's Avatar
 
Join Date: Oct 1999
Posts: 778
Likes: 0
Received 0 Likes on 0 Posts
Cool

Yes I would agree with Phil as someone who has been helping small businesses connect their cable modems to their networks I would highly recommend the Netgear kit. We currently put in about 20 a week so any questions..........

It is amazing how many people think because it is a (cable) modem from a large telecoms company that they are somehow protected from the evil internet.

As a test one of my staff stuck an NT server with no protection on his cable modem at home and watched it take 80 serious attacks in a week and over 200 port sniffs..

One of the serious attacks ended up in someone using it as a store for their MP3 collection unfortunealty it was all japanese!!

Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
33
29 August 2017 07:18 PM
lloydsound
ScoobyNet General
9
14 September 2015 05:34 PM
skipjack
ScoobyNet General
4
25 January 2001 03:01 PM
Scutter
ScoobyNet General
30
30 May 2000 11:05 AM



Quick Reply: For the attention of an IT bod



All times are GMT +1. The time now is 05:15 AM.