Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Computer Trojan Attack/Virus Alert
5 July 2002 | Magnum44

Posted on 07/05/2002 5:56:27 PM PDT by Magnum44

Norten Firewall/Anti-virus has just given me a security alert to the "Backdoor/SubSeven Trojan" coming from IP 209.239.196.152. I have only been surfing FR today (via Earthlink). I am no a computer security expert, so beyond trying to see that my own machine is secure, I do not know how to advise others or how to investigate whether the attempted attack came via FR. Everybody watch your system and make sure you have your Firewalls up and virus checkers on.

Regards


TOPICS: Breaking News
KEYWORDS: computerattack
Navigation: use the links below to view more comments.
first 1-2021-4041-47 next last

1 posted on 07/05/2002 5:56:27 PM PDT by Magnum44
[ Post Reply | Private Reply | View Replies]

To: Magnum44
Hmmm. My browser returns "no such host" for that IP.
2 posted on 07/05/2002 5:59:16 PM PDT by per loin
[ Post Reply | Private Reply | To 1 | View Replies]

To: Magnum44
sub7 is an old one. Try anti-trojan.net and see if you have a trojan onboard already, maybe?
3 posted on 07/05/2002 5:59:57 PM PDT by RedBloodedAmerican
[ Post Reply | Private Reply | To 1 | View Replies]

To: Magnum44
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subseven.html
4 posted on 07/05/2002 6:02:59 PM PDT by Cultural Jihad
[ Post Reply | Private Reply | To 1 | View Replies]

To: Magnum44
Trying whois -h whois.arin.net 209.239.196.152 JPS.Net Corporation (NETBLK-JPS-NETBLK-2) 595 Menlo Drive Rocklin, CA 95765 US Netname: JPS-NETBLK-2 Netblock: 209.239.192.0 - 209.239.223.255 Maintainer: JPS Coordinator: Earthlink Network, Domain Administrator (DAE4-ARIN) arinpoc@corp.earthlink.net +1-626-296-2400 (FAX) 626-296-5113

So some 14 year old downloaded SubSeven.

Admins have an acronym they use: WWF= Weenie With Firewall.(Nothing personal, I used to report them all the time!)

If Norton reports it, it prevented the attack. Norton sells a lot of upgrades by scaring people. Yes, there are L33T punks out there, and worse, always probing, and IMO, the parents that taught them those values need to be stomped in front of them. But it is a fact of life, that on the Net, burglars are trying your "Doors and windows" day and night. If one does have an always on DSL or cable connection, then they need to run SOME kind of protection. A hardware router or a software firewall, like Norton or Zone Alarm.

If you do a google search you will find many sites on the Web claiming a lot of these products are "Snake Oil"- I am not sure of that myself-no matter their faults they are better than none, though there are marketing advantages to a software program that looks like it is "Doing Something".

5 posted on 07/05/2002 6:12:38 PM PDT by Gorzaloon
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gorzaloon
I'm a double WWF. I have a Netgear Firewall Router that catches all the sub-7s and such and also have Norton Internet Security on each machine. Use that mostly to protect my kids. I caught 3 Sub 7 scans in less than an hour while on FR. I know my presence on FR has anything to do with it. My presence on a Cable Modem is the culprit. Being in "the biz" I understood that well enough from the outset to have belt and suspenders.

Folks, if you are sitting on the internet with a cable modem or DSL and are not running an up-to-date virus scanner (and I recommend a firewall) it's like walking out of your house and leaving the doors open.
6 posted on 07/05/2002 6:39:37 PM PDT by NerdDad
[ Post Reply | Private Reply | To 5 | View Replies]

To: NerdDad
Oh great. Here I am on DSL and my daughter just broke up with our computer wizard. At least I have Norton and just updated it.... *sigh*
7 posted on 07/05/2002 6:48:04 PM PDT by Humidston
[ Post Reply | Private Reply | To 6 | View Replies]

To: per loin
That just means there isn't a web server hooked up to that address, there could still be something there sending out stuff.
8 posted on 07/05/2002 6:51:30 PM PDT by bobwoodard
[ Post Reply | Private Reply | To 2 | View Replies]

To: Gorzaloon; All
All responses appreciated. This was mainly a courtesy post. It seems to be either of little concern to a lot of concern depending on whether you have virus detection running. I learned something, too. Keep your guards up.

FRegards,

9 posted on 07/05/2002 6:56:51 PM PDT by Magnum44
[ Post Reply | Private Reply | To 5 | View Replies]

To: Humidston
my daughter just broke up with our computer wizard

Is she someone I should know?

10 posted on 07/05/2002 7:02:07 PM PDT by Flyer
[ Post Reply | Private Reply | To 7 | View Replies]

To: Magnum44
I'm sure you mean well, but this doesn't mean a thing. This is a common everyday event on today's Internet. Your address got hit at random.
11 posted on 07/05/2002 7:12:15 PM PDT by sigSEGV
[ Post Reply | Private Reply | To 1 | View Replies]

To: sigSEGV
I've been getting hit 2 or 3 times a day for the last three weeks with the W32.Klez.E and the variation that end in H@mm and a few other variants as well. It has even pulled my email address out of somebody elses address book and sent the virus out with my address as the sender.

I have Norton and it not only stops incoming viruses (especially the common ones like the Klez. virus) but halts outgoing viruses as well so I know it not on my computer and my scan of my computer 2x a day has been confirming that.

12 posted on 07/05/2002 7:23:34 PM PDT by TheErnFormerlyKnownAsBig
[ Post Reply | Private Reply | To 11 | View Replies]

To: Magnum44
Try HouseCall from Trend Micro. Choose the "Scan without registering" and let it scan your hard drives. It's a web based virus scanner that works VERY well. It's updated with all the newest virus strings, and can remove any viruses it finds automatically if you choose that option.

I use it once a week in conjunction with my McAfee Virus Scanner to keep my system clean.

13 posted on 07/05/2002 7:37:38 PM PDT by usconservative
[ Post Reply | Private Reply | To 1 | View Replies]

To: big ern
I run norton too & my email addy has been pulled by someone & has been sending out infected klez for over a month. i just updated to a new nortong, removed the old one & installed this one from disc & ran the entire scan. my machine is clear, so HOW do we stop the other peoples machines from sending out infected emails using our address?? Is there a way? Any computer geniuses out there?
14 posted on 07/05/2002 8:10:16 PM PDT by blondee123
[ Post Reply | Private Reply | To 12 | View Replies]

To: blondee123
What happens, I believe, is the infected person's address book is being used to send out the messages. This version is taking our email address from the address book and is substituting our address for the real one.

Short of sticking a piece of dynamite in the infected computer there isn't anything we can do but notify those who send us notices saying we sent them a virus that we didn't send the virus.

Of course I'm no computer expert so everything I wrote could be incorrect.LOL

15 posted on 07/05/2002 8:25:27 PM PDT by TheErnFormerlyKnownAsBig
[ Post Reply | Private Reply | To 14 | View Replies]

To: Magnum44
This site, www.grc.com does free port scans and vulnerability checks. It's pretty interesting to read some of his articles, especially his tales of the script-kiddies and what the trojans are all about.
16 posted on 07/05/2002 8:44:15 PM PDT by TC Rider
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #17 Removed by Moderator

To: big ern
The simplest way, is to never give anyone your email address, ever. This may mean never using your email, but as the it's been said - Abstinence is the only 100% guarantee ;0)
18 posted on 07/05/2002 9:21:47 PM PDT by Chad Fairbanks
[ Post Reply | Private Reply | To 15 | View Replies]

To: blondee123
Change your ISP/Email password for starters.
19 posted on 07/05/2002 9:33:49 PM PDT by DB
[ Post Reply | Private Reply | To 14 | View Replies]

To: blondee123
HOW do we stop the other peoples machines from sending out infected emails using our address??

One way is to get rid of micrshaft software and fly free with linux. As well as being free to buy, it is virtually virus free.

20 posted on 07/05/2002 10:35:55 PM PDT by quimby
[ Post Reply | Private Reply | To 14 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-47 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson