Firewall Alert!

Message boards : Cafe SETI : Firewall Alert!
Message board moderation

To post messages, you must log in.

AuthorMessage
Profile littleBouncer
Volunteer tester
Avatar

Send message
Joined: 28 May 99
Posts: 151
Credit: 666,283
RAC: 0
Switzerland
Message 56007 - Posted: 20 Dec 2004, 9:20:05 UTC
Last modified: 20 Dec 2004, 9:21:04 UTC

Everytime I open a thread from "Cafe SETI" I recieve a message from my firewall, that there is a "hacking attack". I A. you (Seti- Staff) , why and what that means:

one of those entries (meanwhile over 90) from my firewall:

2004/12/20 10:12:14 80.161.96.46:80 x.x.x.x:1688 Connection 1688 (TCP)

What has this IP 80.161.96.46 to do with Seti, and/or Cafe SETI ?

Can I trust them?

ID: 56007 · Report as offensive
Ulrich Metzner
Volunteer tester
Avatar

Send message
Joined: 3 Jul 02
Posts: 1256
Credit: 13,565,513
RAC: 13
Germany
Message 56010 - Posted: 20 Dec 2004, 9:35:23 UTC - in response to Message 56007.  
Last modified: 20 Dec 2004, 9:35:42 UTC

> Everytime I open a thread from "Cafe SETI" I recieve a message from my
> firewall, that there is a "hacking attack". I A. you (Seti- Staff) , why and
> what that means:
>
> one of those entries (meanwhile over 90) from my firewall:
>
> 2004/12/20 10:12:14 80.161.96.46:80 x.x.x.x:1688 Connection 1688 (TCP)
>
> What has this IP 80.161.96.46 to do with Seti, and/or Cafe SETI ?
>
> Can I trust them?
>
>

A quick Nettools smartwhois scan reveals this address belongs to
TDC Net
Sletvej 30, A039
DK-8310 Tranbjerg
Denmark
So i think it's from the many statistic signatures linked/embedded in the threads.

Aloha, Uli

ID: 56010 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 56012 - Posted: 20 Dec 2004, 9:47:31 UTC - in response to Message 56007.  
Last modified: 20 Dec 2004, 9:48:04 UTC

> Everytime I open a thread from "Cafe SETI" I recieve a message from my
> firewall, that there is a "hacking attack". I A. you (Seti- Staff) , why and
> what that means:
>
> one of those entries (meanwhile over 90) from my firewall:
>
> 2004/12/20 10:12:14 80.161.96.46:80 x.x.x.x:1688 Connection 1688 (TCP)
>
> What has this IP 80.161.96.46 to do with Seti, and/or Cafe SETI ?
>
> Can I trust them?
>
>

No! I just checked my firewall for incoming events, and there a lot of activity involving Ã…rhus (or Tranbjerg)at the moment! 6 in about 5 minutes!
ID: 56012 · Report as offensive
N/A
Volunteer tester

Send message
Joined: 18 May 01
Posts: 3718
Credit: 93,649
RAC: 0
Message 56016 - Posted: 20 Dec 2004, 10:03:58 UTC - in response to Message 56012.  
Last modified: 25 Dec 2004, 14:08:52 UTC

[root@localhost root]# nslookup 80.161.96.46
Server: 192.168.1.1
Address: 192.168.1.1#53

Non-authoritative answer:
46.96.161.80.in-addr.arpa name = 0x50a1602e.kd4nxx12.adsl-dhcp.tele.dk.

Authoritative answers can be found from:
96.161.80.in-addr.arpa nameserver = auth02.ns.tele.dk.
96.161.80.in-addr.arpa nameserver = auth01.ns.tele.dk.

[root@localhost root]# dig 80.161.96.46

; DiG 9.2.3 80.161.96.46
;; global options: printcmd
;; Got answer:
;; -HEADER- opcode: QUERY, status: NXDOMAIN, id: 26260
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;80.161.96.46. IN A

;; AUTHORITY SECTION:
. 10800 IN SOA A.ROOT-SERVERS.NET. NSTLD.VERISIGN-GRS.COM. 2004121901 1800 900 604800 86400


;; Query time: 45 msec
;; SERVER: 192.168.1.1#53(192.168.1.1)
;; WHEN: Mon Dec 20 05:01:49 2004
;; MSG SIZE rcvd: 105[/pre]Someone else will have to take it from here - I'm a bit busy...

[EDIT] Just checked ipfw.log - No unusual (Though highly suspicious) activity from here. FWIW I'm at 141.155.23.70 right now. Definitely BLOCK :1688 - IANA port reg. says:[pre]nsjtp-data 1688/tcp nsjtp-data
nsjtp-data 1688/udp nsjtp-data
# Orazio Granato
firefox 1689/tcp firefox
firefox 1689/udp firefox
# Mark S. Edwards

[EDIT] Removed <pre> tags
ID: 56016 · Report as offensive
Ken Phillips m0mcw
Volunteer tester
Avatar

Send message
Joined: 2 Feb 00
Posts: 267
Credit: 415,678
RAC: 0
United Kingdom
Message 56019 - Posted: 20 Dec 2004, 10:21:59 UTC
Last modified: 20 Dec 2004, 10:24:22 UTC

As NA has already posted, that ip (according to the windoze tracert command) belongs to whoever has been allocated the dns name of 0x50a1602e.kd4nxx12.adsl-dhcp.tele.dk, somewhere in holland, whose webserver (port 80) is trying to send you a packet, this behaviour, unless I'm being deceived, is consistent with viewing a web page that contains one or more stats signatures, if the relevant images for each of the sigs appears ok, then I can't imagine what else a stats site is trying to do, this does need some serious answers from the likes of boincdk, etc.

As a side note using windoze xp sp2, whenever I view any of these fora with internet explorer 6, I keep getting a blocked cookie alert, even if I allow the offending cookie, my cookie enabled viewing preferences are working ok, so I don't know what that's about either.

Bit of a useless post really, but there you go! We can't all know everything :-0

Ken Phillips

BOINC question? Look here



"The beginning is the most important part of the work." - Plato
ID: 56019 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 56020 - Posted: 20 Dec 2004, 10:30:22 UTC - in response to Message 56019.  

> As a side note using windoze xp sp2, whenever I view any of these fora with
> internet explorer 6, I keep getting a blocked cookie alert, even if I allow
> the offending cookie, my cookie enabled viewing preferences are working ok, so
> I don't know what that's about either.
>

Using Windows XP sp2, I have disabled the firewall feature in it, as I don't trust it! I have my own payed for MacAfee firewall and virusprotection, so I don't suffer from the problems, you mention. So I guess my MacAfee override a lot of these little points of annoyance!
ID: 56020 · Report as offensive
Profile littleBouncer
Volunteer tester
Avatar

Send message
Joined: 28 May 99
Posts: 151
Credit: 666,283
RAC: 0
Switzerland
Message 56022 - Posted: 20 Dec 2004, 10:50:45 UTC - in response to Message 56020.  
Last modified: 20 Dec 2004, 16:07:46 UTC

> I have my own payed for MacAfee firewall and virusprotection,
> so I don't suffer from the problems, you mention. So I guess my MacAfee
> override a lot of these little points of annoyance!
>
=====

I have McAffee too, and what I don't understand why He (80.161.96.46) wants to open a port on my PC (he tries allways a other #, over 100 times)

I have checked by "whois", before I posted, I knew it's came from DK, but the question was, why it appears after reading some threads in "Cafe SETI" (and only this Site).

Thanks a lot for all replies !!!

[EDIT:12.20.04 16:00 UTC] The "signaturs" marked as "cookie" isn't the problem.

ID: 56022 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 56025 - Posted: 20 Dec 2004, 11:18:04 UTC - in response to Message 56022.  
Last modified: 20 Dec 2004, 11:24:06 UTC

>
> I have McAffee too, and what I don't understand why He (80.161.96.46) wants to
> open a port on my PC (he tries allways a other #, over 100 times)
>
> I have checked by "whois", before I posted, I knew it's came from DK, but the
> question was, why it appears after reading some threads in "Cafe SETI".
>
> Thanks a lot for all replies !!!
>
>
I don't know what they are doing out there! But I think it is accidental. Last summer I had LOTS of attacks, involving most of the world, and I became so irritated (Yes, I flame easy!) about it, that I took a screendump and sent it to the Danish Police, the IT crime department, and I got the answer that "they" out there just probes, but if I get attacks from the same IP-adress, they would be happy to be briefed about it! And after a while, the number of attacks dropped, some weeks to none!

So the same information must go to you: If you persistently get attacks from the same, contact your local police, IT- crime department!

I was trying to find an e-mail adress to BOINC.DK, but couldn't see any on their [url=http://www.boinc.dk/index.php] website<a>. Try to google them or search here on their teamsite! But I don't even know if they can explain anything?
ID: 56025 · Report as offensive
Profile littleBouncer
Volunteer tester
Avatar

Send message
Joined: 28 May 99
Posts: 151
Credit: 666,283
RAC: 0
Switzerland
Message 56035 - Posted: 20 Dec 2004, 12:12:23 UTC - in response to Message 56025.  


> So the same information must go to you: If you persistently get attacks from
> the same, contact your local police, IT- crime department!
>
> I was trying to find an e-mail adress to BOINC.DK, but couldn't see any on
> their [url=http://www.boinc.dk/index.php] website<a>. Try to google them
> or search here on their teamsite! But I don't even know if they can explain
> anything?
>
@ Lena!

Thanks for your reply.

I posted 3times at its hostmaster, and announced to make contact with police, but nothing happens. Now I will do as you suggest.


ID: 56035 · Report as offensive
Ubdaddy

Send message
Joined: 24 Aug 02
Posts: 15
Credit: 695,355
RAC: 0
Israel
Message 56040 - Posted: 20 Dec 2004, 12:40:46 UTC

When I started using Zonealarm Pro I tried to track the incoming probs using the Whois function. There is not much that can be done, the hackers uses scanning programs that run through many IP addresses until the find one that responds. You have to set your firewall to block and allow what you want using Expert Rules. A good idea is to test your protection from time to time by test tools available such as on SYMANTEC web site and block the opennings.

Even as I write this down I can see on the Zonealarm tray Icon traffic signs, some of it is my own, some is my ISP provider trying to establish who is connected and who isn't, and some are unsolicited probes. As long as my computer does not respond to the probes I'm fairly safe.

I no longer look at the ZA logfile, ZA, McAfee AV, and anti pests progams all combine to provide a reasonable protection.

Yair

P.S. One of the most dangerous "attacks" out there nowdays, is the Phishing EMails that try to make you give up sensitive information. Never give up any sensitive info unless you initiated the connection and you trust the website.

Yair
ID: 56040 · Report as offensive
N/A
Volunteer tester

Send message
Joined: 18 May 01
Posts: 3718
Credit: 93,649
RAC: 0
Message 56196 - Posted: 21 Dec 2004, 4:41:53 UTC - in response to Message 56019.  

Thanks for pitching in, Ken. FTR: It was nslookup and dig only because my modem/router blocks traceroutes and pings (Damn built-in firewall!). Also I'm using YDL4 which is a Fedora ppc port - No MS here! (OK, except for Excel... that's Microsoft's best product ever.)
ID: 56196 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 57191 - Posted: 25 Dec 2004, 12:43:46 UTC - in response to Message 56007.  

> Everytime I open a thread from "Cafe SETI" I recieve a message from my
> firewall, that there is a "hacking attack". I A. you (Seti- Staff) , why and
> what that means:
>
> one of those entries (meanwhile over 90) from my firewall:
>
> 2004/12/20 10:12:14 80.161.96.46:80 x.x.x.x:1688 Connection 1688 (TCP)
>
> What has this IP 80.161.96.46 to do with Seti, and/or Cafe SETI ?
>
> Can I trust them?
>
>

Look [url=http://setiweb.ssl.berkeley.edu/forum_thread.php?id=7533#57176]here<a>
ID: 57191 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 57212 - Posted: 25 Dec 2004, 13:43:24 UTC - in response to Message 57191.  
Last modified: 25 Dec 2004, 14:02:41 UTC


ID: 57212 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 57213 - Posted: 25 Dec 2004, 13:54:06 UTC - in response to Message 57212.  
Last modified: 25 Dec 2004, 14:36:17 UTC


ID: 57213 · Report as offensive

Message boards : Cafe SETI : Firewall Alert!


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.