The Jedi Academy. THE Place for Jedi training.
Forums
Content
The Academy
Learn
Communicate
Personal


Forums | Academy Discussion
Zone Alarm Going Crazy
Oct 19 2003 11:10pm

n00b
 - Student
n00b
I just checked my zone alarm log and it had grown to 300 megs overnight. Apparently, hundreds of computers have been pinging this machine for some reason. I had to turn off the log, needless to say. You may want to double-check your firewall status to see if this is happening to you as well. I couldn't find any info about what is causing it i.e. virus, trojan, whatever... Anyone know what's going on?
_______________
Gone but hopefully not forgotten...

  Login and add your comment!  
Comments
Oct 22 2003 01:21pm

Havvk
 - Ex-Student
 Havvk

Just close it down, those pop-up thingies really piss me off while im in duels...
_______________
~~~knows secretly that furious sUx0rs~~~
|Defender of Ulthuan|Master of the deagle|Saber staff king|Master of spam|
~~~ You have to be bad to be be evil but you have to be evil to be bad! ~~~
~~~ Will always remember c_M@D as a leader and as a brother -_- ~~~


Oct 21 2003 01:11am

n00b
 - Student
 n00b

Bandit, its got to be the Nachi worm still lingering on the network. If you all remember the dang Blaster worm, Nachi is a clone of it that attempts to patch your computer to stop Blaster. Obviously, its more of a nuisance than a help. One would think RR would be more worried about it and inform their customers some how.
_______________
Gone but hopefully not forgotten...

Oct 20 2003 02:52pm

D@RtHM@UL
 - Student
 D@RtHM@UL

Bandit, don't call ppl n00b :P

Oct 20 2003 01:46pm

Bandit
 - Student
 Bandit

nOOb- my computer is hooked up to RR and I've been getting ICMP pinged like crazy. I've got McAfee set up to block them..but I've been getting hits every10 to 20 seconds it seems...
In fact, I just checked my log and I've had 22 hits in the last three minutes, which is one every 9 seconds or so.

_______________
Part-Time Player (Weekend Warrior).
Recipient of the prestigious "Longest-Post-Ever Award" (bestowed on me by Flash on March 23rd, 2004)


Oct 20 2003 11:04am

Colbey
 - Ex-Student
 Colbey

hehe As to the question about why haven't people patched their shit yet?

There is the first rule of the Sys admin to fall back on.
People are Stupid.

One thing you can do is if you have a good log of originating IPs and times. Get those to the ISP that owns the IP address. They can usually find Abusers/Attackers and handle it accordingly. Or contact customers with possibly infected machines.
_______________
Those that did not kill me, are dead.

Oct 20 2003 04:20am

DJ Sith
 - Jedi Council
 DJ Sith

Alot of that are script kiddies looking for live machines. Get your fancy Zone Alarm to block ICMP. :)
_______________
My car is made of Nerf.

Oct 20 2003 04:08am

n00b
 - Student
 n00b

They're all ICMP pings coming from machines all over Road Runner. Its not restricted to just my domain, its coming from Road Runner domains everywhere.

Its not stopping either, every couple seconds or so this machine gets pinged. Could this be Nachi worm? God, if it is, why haven't people patched their crap yet?
_______________
Gone but hopefully not forgotten...

This comment was edited by n00b on Oct 20 2003 04:10am.

Oct 20 2003 12:40am

DJ Sith
 - Jedi Council
 DJ Sith

Are they all ICMP pings? TCP fragments? SYN's? All from the same IP, from many IP's? If it's TCP or UDP is there a common destination port?
_______________
My car is made of Nerf.

  Login and add your comment!