Notices
ScoobyNet General General Subaru Discussion
Sponsored by:
Sponsored by:

Something weird going in ... ZoneAlarm might be good idea :(

Thread Tools
 
Search this Thread
 
Old 09 August 2001, 10:41 PM
  #1  
EvilBevel
Scooby Regular
Thread Starter
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Unhappy

No scaremongering, but ...

I had about 3000 alarms in the last 3 days from my PC being scanned.

Looks like another trojan becoming active ...

Just make sure that you have some kind of protection on your PC. ZoneAlarm is pretty good and free, but others may be equally useful.

See
Old 09 August 2001, 10:50 PM
  #2  
kryten
Scooby Regular
 
kryten's Avatar
 
Join Date: May 2000
Posts: 869
Likes: 0
Received 0 Likes on 0 Posts
Post

Its good to keep reminding people!

Had a consultant at work this week who complained about a lot of data being sent down his dialup link (which he left connected all day).

It had transferred over 100mb -
netstat -na revealed over 5000 open ports. On reboot, over 2000 ports were opened immediately.

He had a trojan, hadn't updated the virus files in 6 weeks and had no personal firewall. Told him to talk to his IT dept who told him that the laptops were 'self managing' ie he had to do it himself!!!

Regularly updated virus checker plus personal firewall and regular patching isn't just for those of us who run servers....
Old 09 August 2001, 10:51 PM
  #3  
Richard Askew
Scooby Regular
 
Richard Askew's Avatar
 
Join Date: Dec 2000
Location: A land of lap-dancers and Lanson Black Label
Posts: 9,400
Likes: 0
Received 0 Likes on 0 Posts
Post

nah ur ok theo - not scared....
Old 09 August 2001, 11:05 PM
  #4  
EvilBevel
Scooby Regular
Thread Starter
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Post

OK, just to update ... all scans seem to go to port 80, so it may be the Code Red thing relaunching.

If you are not running IIS, you don't have to worry about this one. Still, recommendation of a personal firewall still holds.

Theo
Old 09 August 2001, 11:50 PM
  #5  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

Theo,

it is not so much a <I>relaunch</I>, rather just a continuation of the damage that Code Red II is doing. See
Old 10 August 2001, 01:32 AM
  #6  
kryten
Scooby Regular
 
kryten's Avatar
 
Join Date: May 2000
Posts: 869
Likes: 0
Received 0 Likes on 0 Posts
Post

most of the connections to port 80 at the moment will be code red, or one of its variants/children.

i'm seeing &gt;50 attempts per day.

depends on your ip address: a mate's server is getting 200 attempts per day.

oh well, only 10 days of it to go (until the 1st Sept, anyway).

cleanup of code red 1 is easy as its memory based only: reboot, then patch to stop re-infection.

code red 2 is a bit more tricky....plenty of sites with the info needed though.
Old 10 August 2001, 01:52 AM
  #7  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Reading some of the MS Private newsgroups, Code Red seems to stop the MS Proxy services on BackOffice SBS servers at random.

Interesting side effect...

ChrisB.
Old 10 August 2001, 12:46 PM
  #8  
Ian Griffiths
Scooby Regular
 
Ian Griffiths's Avatar
 
Join Date: Dec 2000
Posts: 302
Likes: 0
Received 0 Likes on 0 Posts
Post

*Groan*

Editted as I read the help file

[This message has been edited by Ian Griffiths (edited 10 August 2001).]
Old 10 August 2001, 12:54 PM
  #9  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

So tonight was a good time to change over to my hardware firewall then?
Old 10 August 2001, 05:11 PM
  #10  
Viagraman
Scooby Newbie
 
Viagraman's Avatar
 
Join Date: Sep 2001
Posts: 6
Likes: 0
Received 0 Likes on 0 Posts
Post

i have had zone alarm and norton av for a while now and i am extremely happy with both.
ZA is certainly good for a freebie !

VM
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
20
22 October 2015 06:12 AM
jobegold@hotmail.co.uk
ScoobyNet General
43
24 September 2015 02:16 PM
RAGGY DOO
General Technical
6
18 September 2015 09:18 PM
Adam Kindness
ScoobyNet General
0
15 September 2015 03:31 PM
blackandz
General Technical
0
12 September 2015 07:01 PM



Quick Reply: Something weird going in ... ZoneAlarm might be good idea :(



All times are GMT +1. The time now is 02:28 PM.