Topic: Dizzy, here is my log file for all the attemped attacks  (Read 3822 times)

0 Members and 1 Guest are viewing this topic.

Offline IAF Lyrkiller

  • Semi retired, but I am still around
  • D.Net Beta Tester
  • Lt. Commander
  • *
  • Posts: 1321
  • Gender: Male
  • JAG & Tech Support
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #20 on: May 04, 2006, 09:55:27 am »
Well, Bonk it happened, while playing on The Forge, I was port attacked.

Here is the log:

Intrusion: MS ASN1 Integer Overflow TCP.
Intruder: 66.18.200.221(2359).
Risk Level: High.
Protocol: TCP.
Attacked IP: CAYNE-23A42D352(172.16.1.10).
Attacked Port: microsoft-ds(445).
Intrusion detected and blocked. All communication with 66.18.200.221 will be blocked for 30 minutes.
Intrusion detected and blocked. All communication with 66.244.71.212 will be blocked for 30 minutes.
Intrusion: MS RPCSS Attack (2).
Intruder: 66.244.71.212(1194).
Risk Level: High.
Protocol: TCP.
Attacked IP: CAYNE-23A42D352(172.16.1.10).
Attacked Port: epmap(135).

Whoever they were, they did not succeed very far. the port attack sw is for SP1

I have SP2 ;D

Give me a break man, if the firewall was off absolutely nothing would have happened if the OS is up to date and properly configured. As you have indicated yourself, the attack was targetted at an out of date OS. If the firewall were left off nothing would have happened and your firewall wouldn't be unneccessarily filtering tcp/ip packets in God only knows how horrible and botched a fashion...

Thank you for helping me to make my case that these software firewalls are completely redundant and do more harm than good.

Out of curiosity, what are your DNS, DHCP and gateway servers on the WAN? Also, do you have UPnP enabled on the router/DSL modem/gateway? I find DSL to be a pain because it takes a lot of these factors out of your control. What model DSL modem do you have? Is this firewall part of the modem firmware?

Bonk, I bypassed my router. I did leave my AV running at least. As for the mdm, it is a ZyXel Prestige 600 series.
The mdm does not have a firmware firewall.




KAT-Lyrkiller
Semi-retired
Captain of the MSC Maus
MEMBER OF KLAW
SILENCE.....I keel you!!!

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #21 on: May 04, 2006, 10:22:35 am »
I can't seem to find a P-600 here:
http://www.zyxel.com/web/support_download_list.php?indexflag=20040906173729
or
http://www.zyxel.com/web/index.php
there are lots of models listed in the product finder drop-down at the left, but no plain old P-600... wanted to download the manual to have a look... ah I have a P330W_V2.0 manual here... seems I went through that Zyxel broadband router with another user... but it looks like the P-600 family is in their DSL CPE product class

Oh yes, here it is, it was Jackle:
http://www.dynaverse.net/forum/index.php/topic,163363947.0.html

It appears the P-600 family has a router and firewall built in...
http://www.portforward.com/english/routers/port_forwarding/ZyXEL/Prestige600/

Have you identified your DNS, DHCP and gateway servers yet? (to allow them full access at your software and modem firewall).

I'll assume you have the oldest model P-623... are you connected to it by ethernet or USB? (please say ethernet...)


Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #22 on: May 04, 2006, 11:13:12 am »
I had a look at the manual for the P623-41_v1-3 it appears it does have a firewall and router/NAT capabilites. These Zyxel products look pretty good. Lots of features...

It is possible that your ISP has configured the Prestige with an admin password you do not have and enabled remote administration... or entirely disabled most of its advanced functions...

P.S. Had your OS been out of date and your firewall off, the AV would not have helped anyway... ;)

Offline IAF Lyrkiller

  • Semi retired, but I am still around
  • D.Net Beta Tester
  • Lt. Commander
  • *
  • Posts: 1321
  • Gender: Male
  • JAG & Tech Support
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #23 on: May 04, 2006, 11:20:38 am »




KAT-Lyrkiller
Semi-retired
Captain of the MSC Maus
MEMBER OF KLAW
SILENCE.....I keel you!!!

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #24 on: May 04, 2006, 11:26:18 am »
I think you mean:

http://us.zyxel.com/web/search.php

And it doesn't work for me... I'll try IE <sigh> Just as Zyxel was beginning to impress me. ;)

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #25 on: May 04, 2006, 11:30:45 am »
Yup their search page works in IE but not Firefox.  ::)

And a search for "Prestige 600" comes up with zero results...  :huh:

Got a direct link to the some of the search results you got?
(http://us.zyxel.com/web/search_result.php gives a mysql result error as nothing is submitted to the script when directly linked, it must be called form their search form)

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #26 on: May 04, 2006, 11:32:45 am »
Does the modem have a sticker or id plate on the bottom or back that indicates the exact model and version?

Offline IAF Lyrkiller

  • Semi retired, but I am still around
  • D.Net Beta Tester
  • Lt. Commander
  • *
  • Posts: 1321
  • Gender: Male
  • JAG & Tech Support
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #27 on: May 04, 2006, 11:42:34 am »
My bad Bonk, the actual model is the 645-M. ;D

it has a slew of info for you. :)




KAT-Lyrkiller
Semi-retired
Captain of the MSC Maus
MEMBER OF KLAW
SILENCE.....I keel you!!!

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #28 on: May 04, 2006, 11:57:55 am »
My bad Bonk, the actual model is the 645-M. ;D

it has a slew of info for you. :)

Cool, I'll check it out. Overall, I'm pretty impressed with the Zyxel products, never used one myself, but they seem to have lots of features and comprehensive manuals.

edit: would that be the P-645-M-11 or the P-645-M-A1?

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #29 on: May 04, 2006, 12:36:53 pm »
Seems there is no manual for the 11 but there is for the A1:
http://us.zyxel.com/web/download/200409098564552005011710400020040811211941_20030512_3.40-P645M-A1_v3.40_UsersGuide.pdf

No USB on this one (thank God). No web interface but telnet administration... interesting.

Seems this one is not a router, just the modem (ADSL bridge), but it does have packet filtering with up to 72 rules. I wonder if the ISP has you locked out?




Offline IAF Lyrkiller

  • Semi retired, but I am still around
  • D.Net Beta Tester
  • Lt. Commander
  • *
  • Posts: 1321
  • Gender: Male
  • JAG & Tech Support
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #30 on: May 04, 2006, 05:17:25 pm »
Bonk, I have come across a very serious iss.

Disabling UPnP caused some really strange things. will not try that again.

had to reset the router just to get back on.




KAT-Lyrkiller
Semi-retired
Captain of the MSC Maus
MEMBER OF KLAW
SILENCE.....I keel you!!!

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #31 on: May 04, 2006, 07:06:11 pm »
That is very strange. I always found it best to disable UPnP, there's just something about automatic port forwarding that is not under my direct control that strikes me as very, very wrong and potentially insecure.

Besides, from what I can tell the P645M-A1 ADSL bridge does not have any UPnP fucntionality anyway? Are you sure its the P645M-A1? Are you configuring it by telnet or with your web browser?

Offline IAF Lyrkiller

  • Semi retired, but I am still around
  • D.Net Beta Tester
  • Lt. Commander
  • *
  • Posts: 1321
  • Gender: Male
  • JAG & Tech Support
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #32 on: May 04, 2006, 07:40:52 pm »
correction enabling UPnP causes problems. and no I am not able to configure the mdm either way.

Oh well... ;D




KAT-Lyrkiller
Semi-retired
Captain of the MSC Maus
MEMBER OF KLAW
SILENCE.....I keel you!!!

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
Re: Dizzy, here is my log file for all the attemped attacks
« Reply #33 on: May 04, 2006, 07:46:14 pm »
Ah, that makes more sense, you're talking about your router... yeah, UPnP is bad news in general.