Results 1 to 13 of 13

Thread: My Firweall is taking a BATTERING

  1. #1
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,176
    Thanks
    3,121
    Thanked
    3,173 times in 1,922 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    My Firweall is taking a BATTERING

    Me and Jiff were talking earlier and he reckons its likely to be the NTL Cable network full of PC's with viruses....

    BUT...today, this am.....2 minutes ago...MY PC tried to access the web with Messenger.....something which I have DISABLED in Options to not run at startup. Its only still there cos Microsloth insists on it for Email to work

    Now, I realise that most of you Hardware/Software Gurus HATE Zonealarm.....but so far I have managed to keep on the right side of it.

    It is showing about one ping style attack every 15 seconds!

    And Messemger attempted yo connect 20 times in rapid succession

    Wassup ? Am I virused?

    This is what is having a go:

    Most are ICMP (ping request?) type 8 subtype 0
    Some are UDP (netbios request?) banging at my 137 port ! ooh err missus
    Messenger is trying to get out of my PC via Port :1900 from my IP address....and also from an IP address I dont recognise as mine...cos its got a different final number !

    I guess its time to put bloody Norton back on...I tried Housecall yesterday......no viruese found, but as its free online, I guess its not exactly up to date....or is it?

    Go one.....shout at me...you know you want to !

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  2. #2
    Senior Member joshwa's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield, UK
    Posts
    4,847
    Thanks
    126
    Thanked
    67 times in 62 posts
    • joshwa's system
      • Motherboard:
      • PC Chips M577 AT/ATX
      • CPU:
      • AMD K6-2 500Mhz
      • Memory:
      • 128mb PC100 SDRAM
      • Storage:
      • 8GB Fujitsu
      • Graphics card(s):
      • 3dfx Voodoo 3 3000 AGP (16mb)
      • PSU:
      • ATX 500watt
      • Case:
      • Midi Tower AT
      • Operating System:
      • Windows 98 SE
      • Monitor(s):
      • 22" TFT Widescreen
    sounds like wechia or blast on the network you're on. welchia pings a lot, and they both try and attack port 137.

    as long as the firewall is picking it up and blocking it you should be okay. just make sure your a/v software is up to date and windows is up to date too

  3. #3
    Bonnet mounted gunsight megah0's Avatar
    Join Date
    Jul 2003
    Location
    Birmingham
    Posts
    3,381
    Thanks
    79
    Thanked
    73 times in 49 posts
    i too installed zone alarm at work and home after the blaster and sobig viruses, so far the uni have not dealt with either very well, in the first 2 days post install i had 760 odd blocked intrusions.
    Recycling consultant

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    housecall is reasonably up to date Zak :-)

    dont forget to do your windows updates as well - it helps prevent the spread of the non email based worms. ( such as blaster )
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #5
    Drop it like it's hot Howard's Avatar
    Join Date
    Jul 2003
    Location
    Surrey, South East
    Posts
    11,731
    Thanks
    14
    Thanked
    42 times in 39 posts
    • Howard's system
      • Motherboard:
      • Asus P5B
      • CPU:
      • Core2Duo E6420 2.13GHz
      • Memory:
      • 2x1gb OCZ DDR2 6400
      • Storage:
      • 250GB & 500GB Seagate
      • Graphics card(s):
      • Inno3d iChill 7900GS
      • PSU:
      • Antec SmartPower 500W
      • Case:
      • Coolermaster Elite 330
      • Monitor(s):
      • 2x AG Neovo F419
      • Internet:
      • Virgin Media 20mbit
    I'm getting EXACTLY the same thing happening here with ZoneAlarm pro!

    I had all sorts of wierd connections in netstat before I got ZoneAlarm. Now it's blocking connections like every 10 seconds. Since I installed it, I've had 43,435 intrusions.

    Home cinema: Toshiba 42XV555DB Full HD LCD | Onkyo TX-SR705 | NAD C352 | Monitor Audio Bronze B2 | Monitor Audio Bronze C | Monitor Audio Bronze BFX | Yamaha NSC120 | BK Monolith sub | Toshiba HD-EP35 HD-DVD | Samsung BD-P1400 BluRay Player | Pioneer DV-575 | Squeezebox3 | Virgin Media V+ Box
    PC: Asus P5B | Core2duo 2.13GHz | 2GB DDR2 PC6400 | Inno3d iChill 7900GS | Auzentech X-Plosion 7.1 | 250GB | 500GB | NEC DVDRW | Dual AG Neovo 19"
    HTPC: | Core2Duo E6420 2.13GHz | 2GB DDR2 | 250GBx2 | Radeon X1300 | Terratec Aureon 7.1 | Windows MCE 2005
    Laptop: 1.5GHz Centrino | 512MB | 60GB | 15" Wide TFT | Wifi | DVDRW


  6. #6
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    I'd be one of the "hardware/software gurus" that don't hate Zone Alarm, then
    (Never had a problem with it on the 50+ installations I've done.)


    MSN Messenger can be disabled - it manages to get itself to launch without a standard registry entry or shortcut in Startup - check here to turn it off:
    http://www.winguides.com/registry/display.php/981/

    I don't know why it should be required for email to work though?
    I've used a similar manual fix to disable MSN Messenger when I first got Windows XP, but I actually use the IM client now so I don't disable it any more


    As for your firewall logging stuff it's blocking, that's good

    If you think your firewall logs are interesting, the firewall logs here at work are showing stacks of ICMP, NetBIOS name/WIN Manager/Microsoft DS probes - plus the odd SQL and SMTP probe thrown in for good measure

    In one 60-second period a few minutes ago I can see 85 entries.


    Remember that a firewall is not the be-all and end-all of security - you should always have AV and keep it up to date, plus run Windows Update periodically to keep your OS patched.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  7. #7
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    For those interested, the original BLASTER worm has since had a handful of copycat variants released, but by less smart people... two suspects have been collared:

    http://www.theregister.co.uk/content/56/32568.html

    http://www.theregister.co.uk/content/56/32649.html


    I have no idea why this worm didn't get as much press coverage as Code Red or Nimda, as it targets thousands of client PCs as opposed to hundreds of servers...
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  8. #8
    No more Mr Nice Guy. Nick's Avatar
    Join Date
    Jul 2003
    Posts
    10,021
    Thanks
    11
    Thanked
    316 times in 141 posts
    I get scanned all the time bud. Just set the notification to 'No' then get on with life. If it don't stop an attack it won't know about it anyway, right now its just telling you what a good job it's doing.

    Not trying to do a thread hijack, but how do I stop MS Messenger loading everytime I start Outlook? It's only annoying cos even though I'm signed out, if I load Outlook and then go and play a game or something afterwards I get a pop up in the game from Messenger if someone messages me. Is a right pain if I'm hosting the game as Alt-Tabbing out to kill messenger freezes the game for everyone.
    Quote Originally Posted by Dareos View Post
    "OH OOOOHH oOOHHHHHHHOOHHHHHHH FILL ME WITH YOUR.... eeww not the stuff from the lab"

  9. #9
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    Thread wrecker

    There's a tab within outlook's options to disable instant messaging integration.

  10. #10
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    Deckard - I'm not certain about that, but is it as straightforward as going to Tools / Options / Other and unchecking the "Enable Instant Messaging" tickbox?

    If that's already disabled and you don't use MSN Messenger, then maybe try disabling it from the instructions on the web site I linked earlier?

    If you do use MSN Messenger occasionally, then I can only suggest killing the process before you start any games.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  11. #11
    Senior Member joshwa's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield, UK
    Posts
    4,847
    Thanks
    126
    Thanked
    67 times in 62 posts
    • joshwa's system
      • Motherboard:
      • PC Chips M577 AT/ATX
      • CPU:
      • AMD K6-2 500Mhz
      • Memory:
      • 128mb PC100 SDRAM
      • Storage:
      • 8GB Fujitsu
      • Graphics card(s):
      • 3dfx Voodoo 3 3000 AGP (16mb)
      • PSU:
      • ATX 500watt
      • Case:
      • Midi Tower AT
      • Operating System:
      • Windows 98 SE
      • Monitor(s):
      • 22" TFT Widescreen
    I use smoothwall, so whilst I may get all this traffic blocked, I don't have pop-ups all the time telling me and on my PC with Zonealarm it just sits happily protected by the smoothwall pc - yay!

  12. #12
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    I use a NAT router so have the same issue as Josh - the only popups I see are when programs try to talk OUT from my PC
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  13. #13
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,176
    Thanks
    3,121
    Thanked
    3,173 times in 1,922 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy
    YOU LOT ROCK:

    A: am glad Housecall is quite upto date, cos I use it every so thanks Moby

    B: I update Windows every week too....thanks Josh for confirming the port number

    C: Howard and Mgoh are clearly seeing it like I do......a personal afront cheers guys for the confirmation

    D: Paul....you da MAN...an IT bloke who uses Zone Alarm

    E:Jiff....what a dude you are. IT response to the numpty at this end..TWICE...once by urgent Text Scare (me cacking my pants)

    F: Deckard.....I dont have Mesenger account....so it isnt on...but it is IMPOSSIBLE to unistall it......XP tells me its essential for Outlook Express, but Inever leave email open in games....in case you send me 44 meg of dirty pictures while Im hosting

    And its COS I dont have Messenger that Jiff was unable tohelp immediately anyway.

    Pheww.....its like the OScars.....thanking everyone

    Im gonna cry a little now

    Cheers guys

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •