Free Republic
Browse · Search
News/Activism
Topics · Post Article


1 posted on 08/23/2003 12:20:56 PM PDT by ex-Texan
[ Post Reply | Private Reply | View Replies ]


Navigation: use the links below to view more comments.
first 1-2021-29 next last
To: ex-Texan
I believe that's the blaster worm trying to get in.
3 posted on 08/23/2003 12:24:40 PM PDT by Rightwing Conspiratr1
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
No problems on my LINUX machines ...
6 posted on 08/23/2003 12:27:14 PM PDT by jimkress (Go away Pat Go away!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
Not "people", it's probably the Blaster worm. Google for it, or look around www.securityfocus.com.
7 posted on 08/23/2003 12:27:36 PM PDT by cryptical
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
It's blaster or nachi. It is coincidence that you were logged into FR.
9 posted on 08/23/2003 12:28:16 PM PDT by Spiff (Have you committed one random act of thoughtcrime today?)
[ Post Reply | Private Reply | To 1 | View Replies ]

FREE PC PROTECTION:

10 posted on 08/23/2003 12:29:06 PM PDT by martin_fierro (A v v n c v l v s M a x i m v s)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
This isn't new. I ran a similar thread HERE about a year and a half ago. I get hits from China, France, Germany, and CA whenever I'm on certain forums in FR.



12 posted on 08/23/2003 12:30:48 PM PDT by gitmo (Press any key to continue ... NOT THAT KEY YOU FOOL!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
port 135 - RPC - remote procedure calls. This has to do with a recent exposed security bug in Windows code. Lots of worms are exploiting it. Not sure if the worm is in your machine or one of your neighbors. Hopefully www.freerepublic.com doesn't have worms.
16 posted on 08/23/2003 12:32:02 PM PDT by dr_who_2
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
Um, yeah, so you're saying that every hack attempt on your PC is some left-wing nut job trying to knock you offline because you're a frequent poster to FR?


18 posted on 08/23/2003 12:33:46 PM PDT by Pyrion
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
Moderator, please edit the title.

I would find "Beware of Hacker and White Rural-American Attacks" to be less offensive.

Thank you.

20 posted on 08/23/2003 12:35:23 PM PDT by timm22
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
This is the info on your badboy hacker.

So9

McAfee Visual Trace  Version 3.25 Results
Target: 195.134.39.66
Date: 8/23/2003 (Saturday), 03:35:52 PM
Nodes: 17


Node Data
Node Net Reg IP Address      Location            Node Name
  17   1   1 195.134.39.66   OSLO                kunde1589.alfanett.no


Packet Data
Node High Low  Avg  Tot  Lost
  17  180  154  163    3    0


Network Data
Network id#: 1
  This is the RIPE Whois server.
  The objects are in RPSL format.
 
  Rights restricted by copyright.
  See http://www.ripe.net/ripencc/pub-services/db/copyright.html

inetnum:      195.134.32.0 - 195.134.39.255
netname:      NO-EAB-CABLE-TV-1
descr:        EAB Tele AS
descr:        Borum, Norway
country:      NO
admin-c:      LAN2-RIPE
tech-c:       LAN2-RIPE
status:       ASSIGNED PA
mnt-by:       RIPE-NCC-NONE-MNT
changed:      leifa@sn.no 19970709
changed:      ripe-dbm@ripe.net 19990706
source:       RIPE

route:        195.134.32.0/19
descr:        ALFANETT NORWAY
origin:       AS8394
mnt-by:       AS8394-MNT
changed:      leifa@e.alfanett.no 20001222
source:       RIPE

person:       Leif Arne Neset
address:      ALFANETT AS
address:      Postboks 8
address:      N-1306 Barum postterminal
address:      Norway
phone:        +47 67 80 62 38
fax-no:       +47 67 80 62 10
e-mail:       leifa@e.alfanett.no
nic-hdl:      LAN2-RIPE
changed:      leifa@sn.no 19971010
changed:      Bjorn.Myrstad@runit.sintef.no 19980407
changed:      Bjorn.Myrstad@runit.sintef.no 19980720
changed:      leifa@e.alfanett.no 19990422
changed:      leifa@e.alfanett.no 19990428
changed:      hostmaster@uninett.no 20000629
changed:      leifa@e.alfanett.no 20001220


Registrant Data
Registrant id#: 1
  Kopibeskyttet, se http://www.norid.no/whois/kopirett.html
  Rights restricted by copyright. See http://www.norid.no/whois/kopirett_eng.html

Domain Information

Domain Name................: alfanett.no
Organization Handle........: ETA9O-NORID
Registrar Handle...........: REG1-NORID
Legal-c Handle.............: LAN2P-NORID
Tech-c Handle..............: LAN2P-NORID
Zone-c Handle..............: LAN2P-NORID
Bill-c Handle..............:
Nameserver Handle..........: DHCP1H-NORID
Nameserver Handle..........: NS512H-NORID

Additional information:
Created:         1999-11-15
Last updated:    1999-12-09

NORID Handle...............: ETA9O-NORID
Organization Name..........: EAB Tele AS (alfanett)
Organization Number........: 0
Post Address...............: Postboks 13
Postal Code................: N-1306
Postal Area................: Barum
Country....................: Norway
Phone Number...............: +47 67 80 62 38
Fax Number.................: +47 67 80 62 10
_____
Visual Trace Copyright ©1997-2001 NeoWorx Inc

26 posted on 08/23/2003 12:40:34 PM PDT by Servant of the Nine (A Goldwater Republican)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan

34 posted on 08/23/2003 12:49:28 PM PDT by Momaw Nadon (The mind is like a parachute. It doesn't work unless it's open.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Graewoulf
techno-ping
36 posted on 08/23/2003 12:51:02 PM PDT by Liz
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
First - if you have Outlook, trash it. Never use it again. Otherwise anything anyone might tell you with regards to machine security will be moot.

May I suggest (assuming you've got a Windows box) using Tiny Personal Firewall? It's free, go to http://www.download.com and search for it. It does wonders for me.

Let it inform you if a program/port combo that you haven't previously approved is being attempted. This way you can approve anything you're working on that requires a resource. Everything else, deny as a rule.

I've got a Win98 box still as my home machine, I rarely if ever update the security, but a simple firewall is all I need to protect myself. Zero problems here. I use the log as an Internet 'weather report' to see what kind of spam traffic is being received by my machine. These days it has been ICMP all the way, thousands and thousands of requests in the past few days. Occasionally there'll be an attempt to see if I'm running a Kazaa server (port 1214) or if I'm dumb enough to be infected with SubSeven (port 27234). Port 135 RPCs do come by occasionally as well as attempts on common named ports and random high-numbered ports.
40 posted on 08/23/2003 12:57:36 PM PDT by thoughtomator (Are we conservatives, or are we Republicans?)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
I finally had to turn off the informational alerts on my zone alarm firewall. "Pings" were coming in from all over the world! It was kind of interesting seeing where they were supposedly located (all over the world), but the new wore off fast. A geek told me the pinging wasn't at my computer necessarily; just random pinging (like a submarine's radar does) to find computers unprotected. Also, the locations shown on the alerts are probably Ghost locations; someone going through fake systems. (I don't understand much of this stuff...I just know zone alarm works)
52 posted on 08/23/2003 1:06:54 PM PDT by Maria S ("..I think the Americans are serious. Bush is not like Clinton. I think this is the end" Uday H.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
Hey Tex! How are ya?
I just set up my brand new Sony Vaio Desktop yesterday, and immediately got infected with the Blaster. Took my geek about two hours to un-infect it.
59 posted on 08/23/2003 1:13:11 PM PDT by EggsAckley (. . . S.U.E. . . . STOP UNNECESSARY EXCERPTING . . . .)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
63.154.16.41

Apparently someone in Oak Brook wants to get to know my Port 135.

Zone Alarm tells me there's a hit every 10 seconds or so to my address, but only a few to Port 135--maybe once a minute, average.

61 posted on 08/23/2003 1:19:44 PM PDT by ninenot (Democrats make mistakes. RINOs don't correct them.--Chesterton (adapted by Ninenot))
[ Post Reply | Private Reply | To 1 | View Replies ]

To: snopercod
may interest
81 posted on 08/23/2003 2:54:23 PM PDT by First_Salute
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
If you are on a DHCP server like DSL, change your IP address and mr. 195.134.39.66 will lose sight of you.
83 posted on 08/23/2003 3:08:29 PM PDT by demlosers
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
bump~
84 posted on 08/23/2003 3:10:08 PM PDT by concentric circles
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ex-Texan
Ya know what's fun? Deliberately opening port 135 on a NAT router just to have it blocked by ZoneAlarm, and then watch the logs fill up with logs of idiots that haven't patched their systems.

Unfortunately I can't do that, because my ISP (Cox HSI) has blocked all connection attempts to port 135 both inbound and outbound at the cable modem.

This is the sort of thing more ISPs need to do.

92 posted on 08/23/2003 3:37:23 PM PDT by Pyrion
[ Post Reply | Private Reply | To 1 | View Replies ]


Navigation: use the links below to view more comments.
first 1-2021-29 next last

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson