Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

High Level Of Internet Probing Activity?
December 31, 2005 | aas

Posted on 12/31/2005 10:52:26 AM PST by an amused spectator

I've been getting a large number of firewall probes all morning - on the order one every minute to two minutes.

Mostly pings and port 1026s (Windows Messenger).

I've been monitoring the WMF exploit for the last couple of days, and when I was checking up on this morning's high activity, I noticed this article:

Worry Watch -- Instant Messenger attacks rise in number and damage (from post-gazette.com, 12/31/2005)

Wonder if someone(s) are trying to use the WMF exploit via Windows Messenger in a big way?


TOPICS: Computers/Internet
KEYWORDS: attacks; im; internet; ping
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-72 next last
BTW, I checked, and I'm logged in.

Or at least I think I am. ;-)

1 posted on 12/31/2005 10:52:28 AM PST by an amused spectator
[ Post Reply | Private Reply | View Replies]

To: an amused spectator

It's most likely a new WMF variant.

And of course, Microsoft has yet to release a patch. Gee, thanks, Redmond!


2 posted on 12/31/2005 10:54:55 AM PST by Terpfen (Libby should hire Phoenix Wright.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: an amused spectator

If you are on highspeed cable or DSL, you get those kinds of things all the time.

Just make sure your firewall software or hardware is operational.


3 posted on 12/31/2005 10:56:11 AM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: an amused spectator
I've also been seeing a lot of port 1026 traffic directed at my networks. Most of it has been spoofed traffic using IANA reserved address space, so all of the inbound requests have landed in the bitbucket.

Considering the volume, it's a sure bet that YAMMW (Yet Another Microsoft Malware Worm) is in play.

4 posted on 12/31/2005 10:58:57 AM PST by Prime Choice (We are RepubliCANs, not RepubliCAN'Ts.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Terpfen; MikeinIraq; N3WBI3
And of course, Microsoft has yet to release a patch. Gee, thanks, Redmond!

Oh, but didn't you hear? Closed source is sooooooooo much more secure than Open Source! (*snerk*)

5 posted on 12/31/2005 11:00:05 AM PST by Prime Choice (We are RepubliCANs, not RepubliCAN'Ts.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TomGuy
If you are on highspeed cable or DSL, you get those kinds of things all the time.

Yes, I'm aware of that. Unless I changed a setting in ZA without realizing it, this is highly abnormal for me. Normally, I get a couple of noticeable taps per day. I'm a computer guru, so I'm not just freaking out over normal activity.

Just wondered if anyone else was getting hammered. (BTW - I've got ZoneAlarm Free)

6 posted on 12/31/2005 11:01:07 AM PST by an amused spectator (Bush Runner! The Donkey is after you! Bush Runner! When he catches you, you're through!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Prime Choice

What exactly does the availability of the code have to do with this? Microsoft isn't on the ball. Apple isn't an open-source company, but you can be sure they'd have a patch for this out by now, even if it was just a temporary fix that disabled the ability to load .wmf files while they worked on something more permanent.


7 posted on 12/31/2005 11:01:24 AM PST by Terpfen (Libby should hire Phoenix Wright.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: an amused spectator

Nothing on my machine (cable broadband), but then I don't have port 1026 open, either.


8 posted on 12/31/2005 11:02:22 AM PST by Philistone (Turning lead into gold...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Prime Choice
I'm getting hammered, but they're bouncing off my firewall. I'm glad I got to my friends' machines immediately when I saw the WMF exploit hanging out there.

Sometimes I wonder if they think I'm strange when I tell them they have to do something to their machine RIGHT AWAY. They don't really say much - they seem to trust my judgement...

9 posted on 12/31/2005 11:04:18 AM PST by an amused spectator (Bush Runner! The Donkey is after you! Bush Runner! When he catches you, you're through!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Philistone
Nothing on my machine (cable broadband), but then I don't have port 1026 open, either.

I assumed that port 1026 was closed and stealthed on my machine, but I could be wrong. I better go check it. Thanks for the tip.

10 posted on 12/31/2005 11:06:12 AM PST by an amused spectator (Bush Runner! The Donkey is after you! Bush Runner! When he catches you, you're through!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: an amused spectator

Love my dial-up. By the time viruses make the trek up hill they're too tired to do much.


11 posted on 12/31/2005 11:06:12 AM PST by Tijeras_Slim ("We're a meat-based society.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: Tijeras_Slim

Ain't it the truth! :-)


12 posted on 12/31/2005 11:06:54 AM PST by an amused spectator (Bush Runner! The Donkey is after you! Bush Runner! When he catches you, you're through!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: an amused spectator

It's probably just the NSA. Hope you're not a terrorist.


13 posted on 12/31/2005 11:07:38 AM PST by Brilliant
[ Post Reply | Private Reply | To 1 | View Replies]

To: Terpfen; MikeinIraq; N3WBI3
What exactly does the availability of the code have to do with this? Microsoft isn't on the ball.

From your remarks, I'd say you haven't run into Golden Eagle or Bush2000 yet. Those two, like every other vapid Microsoft shill, insist that Microsoft's closed-source approach is "more secure" because the bad guys can't see the source code and find weaknesses. They further claim that Microsoft gets its ass handed to it every other day because it's the "most popular" operating system.

Of course, those schmucks also think third-party software is all "Linux" when a bug is found in it. They like to use that argument to bolster their erroneous claim that Microsoft's crap is the "most secure" the market has to offer.

14 posted on 12/31/2005 11:07:41 AM PST by Prime Choice (We are RepubliCANs, not RepubliCAN'Ts.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: an amused spectator
My first reaction was "is port 1026 closed?"

You might also want to Shoot the Messenger. No reason to leave that crap running.

15 posted on 12/31/2005 11:10:16 AM PST by Petronski (I love Cyborg!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Prime Choice

OTOH, most of us Windows users don't bother will all that nonsense. We have our firewalls up, don't open unknown attachments and don't visit the porn sites that are the source of most of the malware out there.

I do a daily scan of my system, automatically, every morning at 2AM, with a constantly updated virus scanner. So far, I've never seen a single thing.

The only time I reboot is when I do an update of something.

Windows XP Professional, with all automatic updates in place and a good firewall, seems pretty darned stable. But, hey...that's just me.


16 posted on 12/31/2005 11:11:25 AM PST by MineralMan (godless atheist)
[ Post Reply | Private Reply | To 14 | View Replies]

To: an amused spectator
Bet it is that evil Bush and his NSA trying to spy on you. Launch a complaint with your local American Criminal Liars Union. Your 4th Amendment rights are being violated - I heard it from the RAT Congresscritters (and a handful of Pubbies also) as well as the NYT, WaPo, LAT and the list goes on.
17 posted on 12/31/2005 11:11:58 AM PST by p23185 (Why isn't attempting to take down a sitting Pres & his Admin considered Sedition?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: an amused spectator

I use ZoneAlarm Free, too.

I have it set to not notify me of every attempted intrusion, because they are too frequent and too distracting.

I just looked at the ZA control panel -- 1262938 access attempts have been blocked. I just installed this new version a few days ago.


18 posted on 12/31/2005 11:12:10 AM PST by TomGuy
[ Post Reply | Private Reply | To 6 | View Replies]

To: Terpfen
What exactly does the availability of the code have to do with this? Microsoft isn't on the ball.

If the code were open, Microsoft wouldn't have to be on the ball, now would they? You or I or self described 'computer gurus' like the OP could write our own patches. :)

19 posted on 12/31/2005 11:13:40 AM PST by 302damnfast
[ Post Reply | Private Reply | To 7 | View Replies]

To: Brilliant
It's probably just the NSA. Hope you're not a terrorist.

Dang! I got cookies for Christmas. I wonder if the EVIL Bush Administration slipped some monitoring cookies into the batch?

20 posted on 12/31/2005 11:14:10 AM PST by an amused spectator (Bush Runner! The Donkey is after you! Bush Runner! When he catches you, you're through!)
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-72 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson