View previous topic :: View next topic |
Author |
Message |
Zed UT Noobie
Joined: 14 Apr 2002 Posts: 2099 Game Trophies: 2
Location: Berkeley, CA
|
Posted: Thu Sep 04, 2003 9:06 pm Post subject: Worm? Is this from the blaster worm? |
|
|
F30002 DCE/RPC DCOM buffer overflow exploit attempt detected.
whats up with this message, its on my firewall over and over.
_________________
New {OCA} Servers
CTF - 213.202.218.5:7877/
BT -213.202.218.5:7977/ |
|
Back to top |
|
|
LeeBe UT Celebrity
Joined: 28 Apr 2002 Posts: 2170 Game Trophies: 2
Location: North East England
|
Posted: Thu Sep 04, 2003 9:35 pm Post subject: |
|
|
Yeah thats from the blaster worm. I got a load of those.
_________________
|
|
Back to top |
|
|
Shaman Tempus's Lad
Joined: 02 Aug 2002 Posts: 70
Location: sat next to tempus
|
Posted: Fri Sep 05, 2003 6:17 pm Post subject: |
|
|
on port 135 no doubt ?
_________________
|
|
Back to top |
|
|
Zed UT Noobie
Joined: 14 Apr 2002 Posts: 2099 Game Trophies: 2
Location: Berkeley, CA
|
|
Back to top |
|
|
LeeBe UT Celebrity
Joined: 28 Apr 2002 Posts: 2170 Game Trophies: 2
Location: North East England
|
Posted: Sat Sep 06, 2003 12:04 am Post subject: |
|
|
weird.... its usually 135, 137 or 139
_________________
|
|
Back to top |
|
|
Shaman Tempus's Lad
Joined: 02 Aug 2002 Posts: 70
Location: sat next to tempus
|
Posted: Sat Sep 06, 2003 2:54 pm Post subject: |
|
|
OMG .....might b a real live hack atempt then lol j/k
is strange though 99.9% of the stuff in my firewall from the blaster worm thingy, was on port 135
_________________
|
|
Back to top |
|
|
roba Angelina's Man
Joined: 14 Apr 2002 Posts: 3240 Game Trophies: 2
Location: Prague, Czech Republic
|
Posted: Sat Sep 06, 2003 3:11 pm Post subject: |
|
|
Firewall logs are funny reading heh, I have there 300+ entries since morning various ports, but 135 is winner
btw Spidy, please choose another (smaller) sig, only very small gfx sigs are allowed on our forums, ty
|
|
Back to top |
|
|
Zed UT Noobie
Joined: 14 Apr 2002 Posts: 2099 Game Trophies: 2
Location: Berkeley, CA
|
Posted: Sat Sep 06, 2003 6:46 pm Post subject: |
|
|
yeah but I've had port 135 blocked for a long time now.
lol spidy, strange thing was when I saw it I disconnected, got a new IP and it happened again about 10 secs later, from the same IP. I then blocekd out 1672 and nothing since then.
I had over 100 attacks in an hour, once I blocked the port, none in a day or so. Very weird.
_________________
New {OCA} Servers
CTF - 213.202.218.5:7877/
BT -213.202.218.5:7977/ |
|
Back to top |
|
|
roba Angelina's Man
Joined: 14 Apr 2002 Posts: 3240 Game Trophies: 2
Location: Prague, Czech Republic
|
Posted: Sat Sep 06, 2003 7:15 pm Post subject: |
|
|
Google says that 1672 is used by IBM Tivoli Netview under AIX. Dont ask me what is it used for lol, but its probably some network thingy:
Quote: | What is IBM Tivoli NetView? IBM Tivoli NetView discovers TCP/IP networks, displays network topologies, correlates and manages events and SNMP traps, monitors network health, and gathers performance data. Tivoli NetView meets the needs of managers of large networks by providing the scalability and flexibility to manage mission-critical environments. |
|
|
Back to top |
|
|
Shaman Tempus's Lad
Joined: 02 Aug 2002 Posts: 70
Location: sat next to tempus
|
Posted: Sat Sep 06, 2003 7:17 pm Post subject: |
|
|
yea i get nothing now ive blocked that port too...
here is a link to a freeware prog to disable dcom and block port 135 if anyones not sure what to do...... http://grc.com/files/DCOMbob.exe...
u can test 4 open ports here to....https://grc.com/x/ne.dll?bh0bkyd2
_________________
|
|
Back to top |
|
|
|