PC Review


Reply
Thread Tools Rate Thread

Continuous intrusion attempts

 
 
=?Utf-8?B?ZHJpdmU1NQ==?=
Guest
Posts: n/a
 
      16th May 2005
XP/Home/SP2/NIS/NAV-As I type this, I am experiencing continuous intrusion
attempts from a Korean IP address (as in 800 attempts in 20 minutes). After
logging off for a few minutes, the same address is attacking again (with the
same frequency). I am going to report this to the administrative and
technical contacts of the network involved ; but in the meantime, does anyone
know whether this indicates a breach of security, or is my NIS simply doing
its job and simply reporting ? Thanks in advance.
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      16th May 2005
From: "drive55" <(E-Mail Removed)>

| XP/Home/SP2/NIS/NAV-As I type this, I am experiencing continuous intrusion
| attempts from a Korean IP address (as in 800 attempts in 20 minutes). After
| logging off for a few minutes, the same address is attacking again (with the
| same frequency). I am going to report this to the administrative and
| technical contacts of the network involved ; but in the meantime, does anyone
| know whether this indicates a breach of security, or is my NIS simply doing
| its job and simply reporting ? Thanks in advance.

It is doing its job !

If you are using Cable or DSL Internet access, I suggest getting a Cable/DSL Router such as
the Linksys BEFSR41. It will act as a simplistic FireWall and shift the Korean IP Host from
seeing the WinXP PC to seeing the Router. There are *many* other benefits to using such a
device as well.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Mike Hall \(MS-MVP\)
Guest
Posts: n/a
 
      16th May 2005
As David pointed out, the firewall is doing its job.. however, I would
recommend that you go to your firewall settings and turn off all but the
most important alerts.. you will be driven insane by them..

--
Mike Hall
MVP - Windows Shell/User
http://dts-l.org/goodpost.htm





"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%(E-Mail Removed)...
> From: "drive55" <(E-Mail Removed)>
>
> | XP/Home/SP2/NIS/NAV-As I type this, I am experiencing continuous
> intrusion
> | attempts from a Korean IP address (as in 800 attempts in 20 minutes).
> After
> | logging off for a few minutes, the same address is attacking again (with
> the
> | same frequency). I am going to report this to the administrative and
> | technical contacts of the network involved ; but in the meantime, does
> anyone
> | know whether this indicates a breach of security, or is my NIS simply
> doing
> | its job and simply reporting ? Thanks in advance.
>
> It is doing its job !
>
> If you are using Cable or DSL Internet access, I suggest getting a
> Cable/DSL Router such as
> the Linksys BEFSR41. It will act as a simplistic FireWall and shift the
> Korean IP Host from
> seeing the WinXP PC to seeing the Router. There are *many* other benefits
> to using such a
> device as well.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



 
Reply With Quote
 
=?Utf-8?B?ZHJpdmU1NQ==?=
Guest
Posts: n/a
 
      16th May 2005


"David H. Lipman" wrote:

> From: "drive55" <(E-Mail Removed)>
>
> | XP/Home/SP2/NIS/NAV-As I type this, I am experiencing continuous intrusion
> | attempts from a Korean IP address (as in 800 attempts in 20 minutes). After
> | logging off for a few minutes, the same address is attacking again (with the
> | same frequency). I am going to report this to the administrative and
> | technical contacts of the network involved ; but in the meantime, does anyone
> | know whether this indicates a breach of security, or is my NIS simply doing
> | its job and simply reporting ? Thanks in advance.
>
> It is doing its job !
>
> If you are using Cable or DSL Internet access, I suggest getting a Cable/DSL Router such as
> the Linksys BEFSR41. It will act as a simplistic FireWall and shift the Korean IP Host from
> seeing the WinXP PC to seeing the Router. There are *many* other benefits to using such a
> device as well.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
> I'm a relative newbie (7 mos.) and know nothing about a Router. Three questions: Will my Norton firewall not do as well as the Router's simplistic firewall ? Did your links at the end of your reply indicate that a Trojan Horse may already be in place ? My firewall log shows a 48 hr. block of the Unused Windows Services Block Trojan Horse for the offending address (218.152.186.93) . Lastly, at this rate (2500 and counting within the last 45 min.) can a security system be simply overwhelmed ? If any of these questions are naive, please accept my apologies. TIA.
>

 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      16th May 2005
From: "drive55" <(E-Mail Removed)>


>> I'm a relative newbie (7 mos.) and know nothing about a Router. Three questions: Will my

Norton
>> firewall not do as well as the Router's simplistic firewall ? Did your links at the end
>> of your reply indicate that a Trojan Horse may already be in place ? My firewall log
>> shows a 48 hr. block of the Unused Windows Services Block Trojan Horse for the offending
>> address (218.152.186.93) . Lastly, at this rate (2500 and counting within the last 45
>> min.) can a security system be simply overwhelmed ? If any of these questions are naive,
>> please accept my apologies. TIA.


The idea of the Router is to not burden the PC with having to deal with multiple intrusions
and alerting. The PC is free to do the work you want it to perform. But most important,
and the reason it is called a Router is that it allows up to 253 nodes to share the one ISP
provided Internet address.

The URLs in my signature are just that. URLs in my signature. They are informative for
those who are infected. If I felt the Original Poster (OP) was infected I would have noted
it in the body.

At those numbers, no the PC will not be overwhelmed. However, it is doing work that is
stealing CPU cycles from you and the work you want to perform.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Leythos
Guest
Posts: n/a
 
      16th May 2005
In article <8EEE85C7-0904-4BB6-B2C1-(E-Mail Removed)>, drive55
@discussions.microsoft.com says...
> XP/Home/SP2/NIS/NAV-As I type this, I am experiencing continuous intrusion
> attempts from a Korean IP address (as in 800 attempts in 20 minutes). After
> logging off for a few minutes, the same address is attacking again (with the
> same frequency). I am going to report this to the administrative and
> technical contacts of the network involved ; but in the meantime, does anyone
> know whether this indicates a breach of security, or is my NIS simply doing
> its job and simply reporting ? Thanks in advance.


I agree with the others in this thread - get a router that provides NAT
and you'll be a lot safer and not see those alerts.

Right now I block more than 50 foreign subnets, some in the /8 range due
to exactly what you are seeing (but my firewall lets me set that up).

If you get a router your PC will only see what YOU (your computer)
connects to, and not the background chatter that you are seeing. One
thing about the router, if you get a Linksys, there is a program called
WallWatcher that can tell you what is happening on your internet
connection with great detail (in/out, source, destination, ports...).

While a NAT Router is NOT A FIREWALL, it's nature (NAT) does limit
inbound connections to only those that YOU initiate.

You can keep your personal firewall application, but it will have little
work to do.

--
--
(E-Mail Removed)
remove 999 in order to email me
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Intrusion attempts from the internet. Bill & Debbie Windows XP Security 7 7th Jul 2007 01:24 AM
intrusion attempts =?Utf-8?B?YmlrZXJjaGlj?= Windows XP Performance 2 29th Aug 2006 04:50 AM
It is normal to get intrusion attempts every 10 minutes? Gary Helfert Anti-Virus 7 24th Jul 2004 06:04 PM
Win2K causes continuous Floppy access attempts Peter Microsoft Windows 2000 Setup 0 12th Sep 2003 12:59 AM
INTRUSION! trying to open port. How to fixed and block such intrusion Peter Microsoft Windows 2000 Applications 0 1st Aug 2003 03:39 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:23 AM.