Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Norton Anti-Virus just blocked this attack on my computer. Who is this?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:29 AM
Original message
Norton Anti-Virus just blocked this attack on my computer. Who is this?
Anyone know? Is it just a spyware?

Intrusion: HTTP Embed Tag NPDSPlay DLL BO.
Intruder: view.atdmt.com (194.129.79.7)(http(80)).
Risk level: Medium
Protocol: TCP
Attacked IP: my name-1(my IP address)
Attacked Port:1712
Printer Friendly | Permalink |  | Top
_testify_ Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:31 AM
Response to Original message
1. From arin.net
Search results for: 194.129.79.7


OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 194.0.0.0 - 194.255.255.255
CIDR: 194.0.0.0/8
NetName: RIPE-CBLK2
NetHandle: NET-194-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: NS-EXT.ISC.ORG
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 1993-07-21
Updated: 2005-08-03

# ARIN WHOIS database, last updated 2006-10-19 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.



Printer Friendly | Permalink |  | Top
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:35 AM
Response to Reply #1
4. Thank you! n/t
Printer Friendly | Permalink |  | Top
 
DrDebug Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 11:04 AM
Response to Reply #1
7. Never use Arin for a trace, but use a good WHOIS
Arin only says that it's Ripe and Ripe controls almost half the internet.

http://whois.domaintools.com/194.129.79.7

IP location: Ireland - Dublin - Dublin - Pipex

inetnum: 194.128.0.0 - 194.131.255.255
org: ORG-UA24-RIPE
netname: UK-PIPEX-194-128-131
descr: UUNET

And that's as far as you can go, because UU Net is one of the worst providers so they'll never take your complaint seriously.
Printer Friendly | Permalink |  | Top
 
mtnester Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:31 AM
Response to Original message
2. Self delete
Edited on Fri Oct-20-06 10:35 AM by mtnester
oops
Printer Friendly | Permalink |  | Top
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:35 AM
Response to Reply #2
3. Thanks so much! n/t
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:36 AM
Response to Original message
5. traceroute and then Whois
mail:~ elfin$ traceroute 94.129.79.7
traceroute to 94.129.79.7 (94.129.79.7), 64 hops max, 40 byte packets
1 nas27.2in1.level3.net (209.247.21.163) 129.086 ms 121.154 ms 115.260 ms
2 ge-7-0-2.hsa2.cincinnati1.level3.net (63.212.221.3) 114.957 ms !H ge-7-0-1.hsa1.cincinnati1.level3.net (63.212.220.2) 111.110 ms !H ge-7-0-2.hsa2.cincinnati1.level3.net (63.212.221.3) 108.212 ms !H
mail:~ elfin$



mail:~ elfin$ whois 194.129.79.7

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 194.0.0.0 - 194.255.255.255
CIDR: 194.0.0.0/8
NetName: RIPE-CBLK2
NetHandle: NET-194-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: NS-EXT.ISC.ORG
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 1993-07-21
Updated: 2005-08-03

# ARIN WHOIS database, last updated 2006-10-19 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
% This is the RIPE Whois query server #2.
% The objects are in RPSL format.
%
% Note: the default output of the RIPE Whois server
% is changed. Your tools may need to be adjusted. See
% http://www.ripe.net/db/news/abuse-proposal-20050331.html
% for more details.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html

% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag

% Information related to '194.128.0.0 - 194.131.255.255'

inetnum: 194.128.0.0 - 194.131.255.255
org: ORG-UA24-RIPE
netname: UK-PIPEX-194-128-131
descr: UUNET
descr: PROVIDER Local Registry
country: GB
admin-c: WERT1-RIPE
tech-c: UPHM1-RIPE
status: ALLOCATED PA
remarks: Please send abuse notification to abuse@uk.uu.net
mnt-by: RIPE-NCC-HM-MNT
mnt-lower: AS1849-MNT
mnt-routes: AS1849-MNT
mnt-routes: WCOM-EMEA-RICE-MNT
mnt-irt: IRT-MCI-GB
source: RIPE # Filtered

organisation: ORG-UA24-RIPE
org-name: UUNET
org-type: LIR
address: c/o UUNET Sweden
P.O. Box 4127
address: SE-17104
address: Solna
address: Sweden
phone: +46 8 5661 7629
phone: +31 20 711 6000
fax-no: +46 8 5661 7236
fax-no: +31 20 711 1784
e-mail: ip@se.mci.com
e-mail: support@uk.uu.net
e-mail: registrar@eu.uu.net
admin-c: AK111-RIPE
admin-c: UIU1-RIPE
admin-c: WERT1-RIPE
admin-c: TONE1-RIPE
admin-c: UE30-RIPE
admin-c: ARK-RIPE
admin-c: AS10646-RIPE
mnt-ref: AS1849-MNT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered

role: WCOM EMEA Registrar Team
address: UUNET / MCI
address: EMEA Network Services
address: J. Muyskenweg 22
address: NL-1096 CJ Amsterdam
address: The Netherlands
phone: +31 20 711 6000
fax-no: +31 20 711 6001
e-mail: registrar@eu.uu.net
admin-c: AK111-RIPE
admin-c: ARK-RIPE
admin-c: HTV5-RIPE
admin-c: TONE1-RIPE
admin-c: USB1-RIPE
tech-c: AK111-RIPE
tech-c: ARK-RIPE
tech-c: HTV5-RIPE
tech-c: TONE1-RIPE
tech-c: USB1-RIPE
nic-hdl: WERT1-RIPE
mnt-by: AS1849-MNT
source: RIPE # Filtered

role: PIPEX Hostmaster
address: UUNET UK
address: Internet House
address: 330 Science Park
address: Milton Road
address: Cambridge
address: CB4 4BZ
address: UK
phone: +44 1223 250122
fax-no: +44 1223 250133
e-mail: support@uk.uu.net
remarks: trouble: Telephone number available 24x7
admin-c: WERT1-RIPE
tech-c: WERT1-RIPE
nic-hdl: UPHM1-RIPE
remarks: UUNET UK
mnt-by: AS1849-MNT
source: RIPE # Filtered

% Information related to '194.129.64.0/20AS9194'

route: 194.129.64.0/20
descr: UUNet Global Hosting - UK5
origin: AS9194
mnt-by: MCI-MNT
source: RIPE # Filtered
Printer Friendly | Permalink |  | Top
 
Ian David Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 10:51 AM
Response to Original message
6. That might be connected to this...
Oct 19, 2006

* <10:45 EDT> SpamCop and others are monitoring a huge global increase in spam volumes that started late last week. Networks are reporting anywhere from 30-50% increases in spam volume. On our system, this is causing occasional mail delays as our filtering systems struggle with the load. We're working on installing more systems in the filters to increase our capacity but this won't be finished for around a week. In the meantime, we may have delays during the middle of the day. We're aware of the problem and doing what we can to mitigate it until all the new systems are operational.
http://mail.spamcop.net/news.php
Printer Friendly | Permalink |  | Top
 
zreosumgame Donating Member (862 posts) Send PM | Profile | Ignore Fri Oct-20-06 11:17 AM
Response to Original message
8. basically some script-kiddie seeing if you were silly enough to install
IE 7. Sadly a lot of folks will....
Printer Friendly | Permalink |  | Top
 
Marnieworld Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 11:44 AM
Response to Reply #8
9. what's wrong with it?
ie7?
Printer Friendly | Permalink |  | Top
 
zreosumgame Donating Member (862 posts) Send PM | Profile | Ignore Fri Oct-20-06 01:44 PM
Response to Reply #9
10. A) it's IE LOL
B) within hours the first exploit was found that will let people install mal-ware on your PC. Expect more...
Printer Friendly | Permalink |  | Top
 
Igel Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 02:23 PM
Response to Reply #9
12. With IE 6 there were multiple ways for somebody to
get to your computer. Too many holes, too many problems: think of them as gates to your hard drive and data. They've spent years issuing patches for all the goofs and lapses. Gives "Bill Gates" a new meaning.

They bring out IE 7. You want to believe that there are no holes, goofs, or mistakes in the code? I don't. It's a beta version for public release, and will be for the next year or two.

People lauded Firefox. But it also had problems that needed repair. Fewer, but they were there. They were fixed more quickly than Microsoft fixed things, but hey, MS deserves its abbreviation.

I use old software. And I keep most of the whistles and bells on my browser turned off. I have Netscape with everything enabled, pretty much ... but only use it for Flash-heavy webpages that I trust. In other words, a couple of times a week, maybe.
Printer Friendly | Permalink |  | Top
 
obreaslan Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 02:13 PM
Response to Reply #8
11. Ha ha ha! I just glanced at your post....
And saw "Sadly a lot of folks will...." and then the picture of Clinton in your sig line. I thought you were saying that sadly, a lot of folks will blame Clinton. :rofl:

I just thought you were trying to be funny. :D



Printer Friendly | Permalink |  | Top
 
mvd Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-20-06 02:27 PM
Response to Original message
13. Here's a writeup on it
Probably someone trying a media player exploit.

http://securityresponse.symantec.com/avcenter/nis_ids/s21551.html

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sat May 11th 2024, 02:51 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC