Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Need Help: FR has become Norton Security Threat
7-1-04 | cgk

Posted on 07/01/2004 9:36:01 AM PDT by cgk



TOPICS: Free Republic; Miscellaneous; Your Opinion/Questions
KEYWORDS: help; techindex
Last night Norton had an intrusion attempt while I was accessing FR, and when I blocked the attempt, my connection to FR was "refused." I had to restart my computer because the rest of the web "worked", just not FR.

This morning, while accessing FR (browsing, and then again clicking my FR pager, the pop-up window), another intrusion attempt, this time I recorded the details which you can see a portion of above (it wouldn't let me copy the whole Norton screen).

It said FR was the source. This has never happened before and I've been using Norton for awhile, and the FR pager forever. Any ideas on how to work around this, or determine what the problem is? Thank you!

1 posted on 07/01/2004 9:36:02 AM PDT by cgk
[ Post Reply | Private Reply | View Replies]

To: Jim Robinson; John Robinson; Admin Moderator

ping... thanks!


2 posted on 07/01/2004 9:36:40 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

Past two days; I received similar when going to "list older threads". "Page not displayed". Three times. Suggests it's a live "assault" as opposed to a bot-routine.


3 posted on 07/01/2004 9:37:56 AM PDT by Alia (California -- It's Groovy! Baby!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Alia

It seems to have only happened to me when using the FR pager... how did you get around it? Just accept the attempt?


4 posted on 07/01/2004 9:39:12 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: *tech_index; Ernest_at_the_Beach; ShadowAce

Hmmmmm. Ping.


5 posted on 07/01/2004 9:42:41 AM PDT by martin_fierro
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

BTW - I am on FR again now because I rebooted my pc. I could not access FR otherwise. And I've skipped using the "pager" until I know what to do. :)


6 posted on 07/01/2004 9:44:02 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

I have Norton, but I never use pager,
and have not had any problem with FR
via Norton.


7 posted on 07/01/2004 9:45:48 AM PDT by onyx
[ Post Reply | Private Reply | To 6 | View Replies]

To: cgk

Thanks for the post. I use norton too but have never encountered any problem like this.


8 posted on 07/01/2004 9:50:51 AM PDT by Fiddlstix (This Tagline for sale. (Presented by TagLines R US))
[ Post Reply | Private Reply | To 2 | View Replies]

To: cgk

The IP seems to match FR's, but it seems unlikely that MSSQL was involved.


9 posted on 07/01/2004 9:50:55 AM PDT by HAL9000
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk
Says low risk. I don't have an answer, but we have been working over here:

PestPatrol Shares Spyware Lessons ( Company will offer database of known... free.)

This is a resource thread, not an answer thread. It gives an idea of the magnitude and variety of the threats!!!

10 posted on 07/01/2004 9:51:19 AM PDT by Ernest_at_the_Beach (.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Fiddlstix

That's the strange thing. I've had Norton Internet Security for a short while now and this is the first time it's ever happened. Twice in 12 hours or so.


11 posted on 07/01/2004 9:52:39 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: HAL9000

I don't even know what MSSQL is ;)


12 posted on 07/01/2004 9:53:13 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: cgk
I'm guessing Norton "thinks" it's an actual intruder. It shows up as a "Low" threat.

I'm just guessing. I use Sygate Personal Firewall and for antivirus I use AVG since it's been documented a number of times in PC Magazine that Nortons antivirus and firewall software products produce "false positives" on numerous occasions.

13 posted on 07/01/2004 9:54:01 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

It is a null packet related to SQL, probably a harmless frame used in database queries. Accept it and choose not to notify in the future.


14 posted on 07/01/2004 9:54:37 AM PDT by Lunatic Fringe (John F-ing Kerry??? NO... F-ING... WAY!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

MSSQL is Microsoft's SQL server.


15 posted on 07/01/2004 9:54:39 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: BigSkyFreeper

Not from Microsoft themselves, but MSSQL is the Microsoft based SQL (database) server.


16 posted on 07/01/2004 9:56:46 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: cgk
I don't even know what MSSQL is ;)

I think that is the SQL (Relational Database )

17 posted on 07/01/2004 9:57:48 AM PDT by Ernest_at_the_Beach (.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: cgk

Did the page you were viewing have pictures?


18 posted on 07/01/2004 9:58:07 AM PDT by Bikers4Bush (Flood waters rising, heading for more conservative ground. Vote for true conservatives!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BigSkyFreeper; Lunatic Fringe

Thank you for the clarification. I've heard that about norton also... ran a Housecall scan the other day in fact because Norton came up empty but I have a file I can't delete and read it could be a worm or some sort. Housecall came up empty also, so I assumed it was wrong, but I still have this 0 byte folder I can't get rid of. Even downloaded MoveOnBoot, no fix.


19 posted on 07/01/2004 9:59:17 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: cgk

A couple of months ago I kept getting strange pop-ups while on FR. I think there was a discussion on it also. No problem lately but at the time it did not affect all.


20 posted on 07/01/2004 9:59:24 AM PDT by cinFLA
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Thank you... reading it now. (wow, extensive!!!)


21 posted on 07/01/2004 9:59:49 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: cgk

Change to Arial font because it is easier to read.


22 posted on 07/01/2004 10:00:30 AM PDT by bmwcyle (<a href="http://www.johnkerry.com/" target="_blank">miserable failure)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bikers4Bush

Possibly? It was trying to open "my comments" via the pager, which opens fine now, but there are pics in the page...


23 posted on 07/01/2004 10:00:58 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 18 | View Replies]

To: cgk

If the file or folder is in use by the system as a background task process, Windows won't let you delete it until you close the program or end the process in the task manager.


24 posted on 07/01/2004 10:02:43 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 19 | View Replies]

To: bmwcyle

Good idea.


25 posted on 07/01/2004 10:03:02 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 22 | View Replies]

To: cgk

Norton Internet Security is known to be "highly strung" when it comes to issuing alerts. The usual advice is to set it to report only alerts of a critical nature, which should eliminate bogus alerts like the one you encountered here.


26 posted on 07/01/2004 10:04:37 AM PDT by Leroy S. Mort
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leroy S. Mort

That's what I would recommend. Any non-threatening alert would spook any "newbie" into thinking some intruder is snooping around inside the computer.


27 posted on 07/01/2004 10:06:40 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: cgk
The first step is to stop using IE. Get Mozilla.

Garde la Foi, mes amis! Nous nous sommes les sauveurs de la République! Maintenant et Toujours!
(Keep the Faith, my friends! We are the saviors of the Republic! Now and Forever!)

LonePalm, le Républicain du verre cassé (The Broken Glass Republican)

28 posted on 07/01/2004 10:08:25 AM PDT by LonePalm (Commander and Chef)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

The latest thing in spyware is to attach it to a .jpg or like file so that when it is accessed it loads the spyware.

It's possible that a linked picture had spyware embedded in it.


29 posted on 07/01/2004 10:09:05 AM PDT by Bikers4Bush (Flood waters rising, heading for more conservative ground. Vote for true conservatives!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: BigSkyFreeper; Leroy S. Mort

Okay... I opened the settings, and the personal firewall settings are on "medium (recommended)". Although you see it notified me to the low threat above. Should I change it to "high" only?


30 posted on 07/01/2004 10:09:58 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 27 | View Replies]

To: LonePalm

LOL! Using Mozilla since the reboot.


31 posted on 07/01/2004 10:10:26 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 28 | View Replies]

To: cgk

The Norton screenshot does not show a port number, but according to the tcpdump utility on Mac OS X, the FR pager is sending traffic to port 51524.


32 posted on 07/01/2004 10:10:43 AM PDT by HAL9000
[ Post Reply | Private Reply | To 1 | View Replies]

To: cgk

That's the usual recommendation if you don't want to be bugged by non critical alerts.


33 posted on 07/01/2004 10:12:44 AM PDT by Leroy S. Mort
[ Post Reply | Private Reply | To 30 | View Replies]

To: HAL9000

Since I restarted, I can't find the details of the last "attack". It wiped them all. If it happens again, I'll look for the port # and see if it's the same.


34 posted on 07/01/2004 10:15:58 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 32 | View Replies]

To: cgk
Put it on high for a day or so and see what happens. If that doesn't work, try and see if you can get Nortons to remember your preferences based on the websites you visit. For instance, you don't want to be warned when you go to the FR page, tell Nortons that you don't want to see that warning when you log into your pager.

I guess what I am trying to say is, for example, the first time I run an application, Sygate asks me if I want that application to have access to the internet, I check "Remember my answer" and click Yes. From that point on, I can open my browser and Sygate remembers that I wanted the browser to be able to access the web and doesn't need to ask me again since I told it to remember my answer.

Otherwise, if I clicked yes without checking the box, it asks me everytime I open the browser.

35 posted on 07/01/2004 10:17:55 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: BigSkyFreeper; cgk
I am new to Firefox (Mozilla ),and it seemed to me yesterday that it had the capability as described also.

Without Norton that is.
36 posted on 07/01/2004 10:25:20 AM PDT by Ernest_at_the_Beach (.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Ernest_at_the_Beach; BigSkyFreeper; Bikers4Bush; Leroy S. Mort

Thank you to all of you who have tried to help me with this!

Okay... I have Mozilla 1.6. I just read their FAQ and I will download Firefox now. I am pretty sure that both occurrences happened when I was using IE. Old habits are hard to break and all that. Based on what Ernest said on the other thread he linked to in #10, it looks like I need to download some more stuff. (adaware doesn't seem to be enough).

I just tried the FR pager again in both IE and Mozilla and nothing happened. It may be what Bikers said - a picture with something embedded from some thread somewhere, although it won't repeat itself (Good!!!!).

I'll reset my firewall to high and see how that works.

Hopefully this thread will fizzle. Meaning no more problems for me or anyone else. ;)


37 posted on 07/01/2004 11:05:42 AM PDT by cgk (3000+ 9/11. Pearl, Fallujah, Berg, Jacobs, Scroggs, Johnson, Sun-il... Never forget. Never Again!)
[ Post Reply | Private Reply | To 36 | View Replies]

To: cgk

Thanks to FReepers, I moved to Mozilla Firefox yesterday.


38 posted on 07/01/2004 11:27:48 AM PDT by Alia (California -- It's Groovy! Baby!)
[ Post Reply | Private Reply | To 37 | View Replies]

To: HAL9000; cgk; Alia; All
The pager and everything else on this site are just web pages served by a regular web server. The pages are sent only on the port your machine opens when it contacts our server.

Your machine chooses an unused local port when it makes its "call" to FR. 51,524 or any of about 30,000 to 60,000 other possibilities. Sometimes it chooses a port that is known (to the firewall) to be used by some service (such as MSSQL) and because some firewalls are less than intelligent, not knowing or caring from where the connection originates (the local machine), they sniff any old traffic with abandon, and occasionally squawk when they sample a known exploit signature (just a string of bytes not necessarily representing malice.)

Imagine the same firewall software configured to alert whenever it sees "cat." (Advocated by dog enthusiasts, no doubt a critical alert.) It now constantly goes off on any -cat- word: advocate, allocate, catalog, vacation, etc. This is basically how the exploit detection mechanism works, it's just looking for a pattern of bits, sometimes in a particular place (the third through fifth letters perhaps in the cat example--alerting on vacation but not catalog), sometimes it doesn't have the luxury of specific location, and searches the entire packet.

Some problems of false positives can be alleviated switching to a "smart" firewall: a stateful one. Especially smart firewalls "speak" the application protocols--to decipher the meaning of the packet (effectively knowing that vacation is not feline, don't alert.)

39 posted on 07/01/2004 12:45:05 PM PDT by John Robinson
[ Post Reply | Private Reply | To 32 | View Replies]

To: John Robinson
Great explanation, thank you very much. As a rule, my "fr port" encounters little to no problems at all. I found it curious when I saw the post by ckg; and the timing matching closely to my past two day's, limited, experience "with no page found". I figured my own experience to be due to some system/communication glitch.

You really do explain this well, and of course, I've got to ask you why, suddenly, similar experiences -- sort of a web page server "broken window" type of system error? Could it have just been a sequence of "cat" appearing on a thread/post page, activating port unreponses, possibly in ports configured similarly?

40 posted on 07/01/2004 2:22:46 PM PDT by Alia (California -- It's Groovy! Baby!)
[ Post Reply | Private Reply | To 39 | View Replies]

To: cgk

Are you logged in?


41 posted on 07/02/2004 4:59:07 AM PDT by RWR8189 (Its Morning in America Again!)
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #42 Removed by Moderator

To: starboardlist

Opera? I've not heard of this before. I'll take a look. Thanks for the recommendation.


43 posted on 07/02/2004 12:25:13 PM PDT by Alia (California -- It's Groovy! Baby!)
[ Post Reply | Private Reply | To 42 | View Replies]

To: Ernest_at_the_Beach

Structured Query Language


44 posted on 07/05/2004 6:11:58 AM PDT by snopercod (The politicians make the weather then say "$hit, it's raining"!)
[ Post Reply | Private Reply | To 17 | View Replies]

To: LonePalm
can one use both Mozilla and IE?

I am afraid that I will not be able to use certain web sites that I need for business if I only use Mozilla.

45 posted on 07/07/2004 9:17:04 PM PDT by Nachum (HATRIOTS = LIBS)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Nachum
Yes you can use both. My VERY large company (100K+ employees) has standardized on Mozilla. We only have a few legacy apps that require IE.

Garde la Foi, mes amis! Nous nous sommes les sauveurs de la République! Maintenant et Toujours!
(Keep the Faith, my friends! We are the saviors of the Republic! Now and Forever!)

LonePalm, le Républicain du verre cassé (The Broken Glass Republican)

46 posted on 07/08/2004 5:15:50 AM PDT by LonePalm (Commander and Chef)
[ Post Reply | Private Reply | To 45 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson