General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

Norton Firewall - Trojan Horse matched?

Thread Tools
 
Search this Thread
 
Old Nov 12, 2004 | 08:11 AM
  #1  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default Norton Firewall - Trojan Horse matched?

I keep getting a warning coming up on my PC from Norton Firewall telling me its blocked an attempt to hack my PC...

Security alert - High risk

Attempted to connect to local computer using the NetBus Trojan horse blocked...

This happens about once an hour, I've run both my anti virus programs and they haven't picked anything up, just about to run Spybot and see if that finds anything, but other than that I'm lost...

Anyone got any ideas?
Reply
Old Nov 12, 2004 | 10:00 PM
  #2  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

Reply
Old Nov 12, 2004 | 10:01 PM
  #3  
BillyCabrio's Avatar
BillyCabrio
10K+ Poster!!
iTrader: (1)
 
Joined: Jun 2003
Posts: 13,450
Likes: 2
From: Dartford, Kent - Home of the two way one way system.
Default

I've had them all night mate, nowt to worry about if the firewall has got'em.
Reply
Old Nov 12, 2004 | 10:01 PM
  #4  
rsbabyrs's Avatar
rsbabyrs
Wahay!! I've lost my Virginity!!
 
Joined: Nov 2004
Posts: 50
Likes: 0
Default

This can be an attempt by your isp to check you are still online and is not necerserally an attack.
check the i.p address and post here and i can tell you who it is.
most hackers these days wouldnt use this type of atack as it leaves an ip which is tracable.
Reply
Old Nov 12, 2004 | 10:07 PM
  #5  
Fast Guy's Avatar
Fast Guy
Advanced PassionFord User
20 Year Member
 
Joined: Sep 2003
Posts: 1,529
Likes: 9
From: N Yorks
Default

If Norton's blocked it, then it's done it's job. Make sure you keep it uptodate and don't worry about it.
Reply
Old Nov 12, 2004 | 10:09 PM
  #6  
Jim Galbally's Avatar
Jim Galbally
20K+ Super Poster.
 
Joined: May 2003
Posts: 20,599
Likes: 0
From: Ramsgate, Kent Drives: E39 530D Touring
Default

agreed, just ignore it... i now turn off all messages, as theyre too frequent.
Reply
Old Nov 12, 2004 | 11:14 PM
  #7  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

Ok I'll post the IP address next time it happens, cheers
Reply

Trending Topics

Old Nov 12, 2004 | 11:30 PM
  #8  
Dilly's Avatar
Dilly
PassionFord Regular
20 Year Member
 
Joined: Apr 2004
Posts: 431
Likes: 0
From: luton
Default

keep getting the same on mine, don't think it's anything to worry about
Reply
Old Nov 12, 2004 | 11:57 PM
  #9  
Dilly's Avatar
Dilly
PassionFord Regular
20 Year Member
 
Joined: Apr 2004
Posts: 431
Likes: 0
From: luton
Default

IP address will be stored in your log file
Reply
Old Nov 13, 2004 | 12:40 AM
  #10  
Dan B's Avatar
Dan B
Advanced PassionFord User
 
Joined: Apr 2004
Posts: 2,364
Likes: 0
Default

My router's firewall blocks NetBus scans all the time......basically, it's either an already-infected machine scanning for other machines to infect, or a "central" server looking for already-infected machines to remote-control them.

If your firewall is blocking them, you can either ignore them or you can grab the IP, identify the culprit using something like the third box down in the middle column (assuming it's working now), and report them to their ISP.
Reply
Old Nov 13, 2004 | 04:07 PM
  #11  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

Fookin hell a different one now....

Attempt to connect to local computer using the Back Orifice Trojan horse blocked

Time: 16:58
Date: 13/11/2004
Protocol: TCP (Inbound)
Remote Address: 80.41.103.205 : 2720

Reply
Old Nov 13, 2004 | 04:19 PM
  #12  
rsbabyrs's Avatar
rsbabyrs
Wahay!! I've lost my Virginity!!
 
Joined: Nov 2004
Posts: 50
Likes: 0
Default

Looks malicious to me now.

Server Used: [ whois.ripe.net ]

80.41.103.205 = [ ] This is the RIPE Whois tertiary server.
The objects are in RPSL format.
Rights restricted by copyright.
See http://www.ripe.net/db/copyright.html
Reply
Old Nov 13, 2004 | 04:23 PM
  #13  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

so someone is knowingly trying to hack my pc then

Ain't they got anything better to do?
Reply
Old Nov 13, 2004 | 04:33 PM
  #14  
Dan B's Avatar
Dan B
Advanced PassionFord User
 
Joined: Apr 2004
Posts: 2,364
Likes: 0
Default

inetnum: 80.40.0.0 - 80.47.255.255
org: ORG-TUL3-RIPE
netname: UK-TELINCO-20011123
descr: PROVIDER Local Registry
country: GB
tech-c: TU935-RIPE
admin-c: TU935-RIPE
status: ALLOCATED PA
notify: hostmaster@uk.tiscali.com

trouble: Information: http://www.tiscali.com
trouble: Concerning abuse and spam ... mailto: abuse@uk.tiscali.com

Forward that exact log to the above bold-highlighted address...
Reply
Old Nov 13, 2004 | 04:36 PM
  #15  
rsbabyrs's Avatar
rsbabyrs
Wahay!! I've lost my Virginity!!
 
Joined: Nov 2004
Posts: 50
Likes: 0
Default

Yes, someone is trying to get into your machine.
What are you doing when the attack comes ?
Are you on a forum ?
Reply
Old Nov 13, 2004 | 04:52 PM
  #16  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

erm I'm on PF and ebay I think...., not 100%, if it happens again I'll see what sites I'm on
Reply
Old Nov 13, 2004 | 04:53 PM
  #17  
Dan B's Avatar
Dan B
Advanced PassionFord User
 
Joined: Apr 2004
Posts: 2,364
Likes: 0
Default

Back Orifice trojan-horse, if it works like most other trojans, will just scan a range of IP addresses set by the trojan, for vulnerable machines to which it can spread itself......I doubt what's happened is a manual-attack, more a case of an infected machine automatically trying to spread the trojan to other vulnerable machines.

Report it, all the same, though...
Reply
Old Nov 13, 2004 | 04:55 PM
  #18  
rsbabyrs's Avatar
rsbabyrs
Wahay!! I've lost my Virginity!!
 
Joined: Nov 2004
Posts: 50
Likes: 0
Default

This type is malicious though and is used to look for open ports, it will tell people scanning of open ports in a range and give them entry.
I`m not saying this is the case as it also is a spread virus like mentioned above.
Reply
Old Nov 13, 2004 | 04:59 PM
  #19  
Dan B's Avatar
Dan B
Advanced PassionFord User
 
Joined: Apr 2004
Posts: 2,364
Likes: 0
Default

A port-scan would show up slightly differently to a firewall that's blocking it, though, you'd get LOTS of entries or pop-up windows to show you of the activity hitting sequential ports...

Not saying that the activity noted above isn't a manual attack, but from experience of dealing with this kind of thing in work, it's "normally" the trojan trying to spread itself automatically......you'll probably find, in 99 out of 100 cases, that the person whose computer it is doesn't even know their own computer is doing it.

Also, port-scans tend to go for the more "popular" ports, like 25 (SMTP), 21 (FTP), telnet (23), and so on, as they're more easily abused by someone who knows what to do with them.
Reply
Old Nov 14, 2004 | 01:21 AM
  #20  
Wazzzer's Avatar
Wazzzer
Thread Starter
PassionFord Post Whore!!
 
Joined: May 2003
Posts: 4,723
Likes: 0
From: Isle of Wight
Default

the more I block the more try to attack....

Time: 22:55
Date: 13/11/2004
Protocol: TCP (Inbound)
Remote Address: 80.108.113.16 : 3052
Local Address: 80.41.212.224 : 27374 (I forgot this bit last time)

The only thing I was logged into was messenger, so it looks like its trying to spread itself through there....

Reply
Old Nov 14, 2004 | 09:02 AM
  #21  
Eagle's Avatar
Eagle
Super Moderator
20 Year Member
iTrader: (2)
 
Joined: Jun 2003
Posts: 18,610
Likes: 4
From: somwhere in wow
Default

good site to check your protection


http://www.grc.com/default.htm
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
nicodinho
Ford Non RS / XR / ST parts for sale.
6
Oct 7, 2015 12:56 PM
AJC
Cars for Sale
1
Oct 1, 2015 06:47 PM
Flatlinedan
Technical help Q & A
3
Sep 18, 2015 12:41 PM
gambo08
Fiesta RS1800/RS Turbo
5
Sep 16, 2015 08:10 PM
bigryrs
Ford RS Turbo Parts for Sale
2
Sep 7, 2015 06:45 PM




All times are GMT. The time now is 05:33 AM.