Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 25, 2008, 04:38:04 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
176893
Posts
20915
Topics
50723
Members
Latest Member:
flangad
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v2
Was I attacked? [Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: Was I attacked? [Resolved] (Read 2038 times)
Bubu74
Comodo Loves me
Offline
Posts: 177
Was I attacked? [Resolved]
«
on:
January 07, 2007, 08:25:41 AM »
Yesterday while using DC++, I received a two warnings about Denial of Service attack. Here is one log entry:
Date/Time :2007-01-07 01:01:10
Severity :High
Reporter :Network Monitor
Description: DDOS Attack (UDP Flood)
Duration: 23 seconds # of packets: 229 # of attackers: 278
Attacker(s): 83.227.108.205, 85.157.12.115, (... 19 more different IP addresses...)
The firewall has switched to EMERGENCY mode
This happened before I opened a dedicated port for DC++ in CPF (it was my first use of DC++ after instaling CPF). After that, I didn't receive additional warnings, and continued to use DC++ without any trouble.
Was I really attacked, or was it just a normal p2p traffic, missinterpreted by CPF. If so, many thanks to Comodo for protecting me
.
Note that I am behind a NAT router/firewall...
«
Last Edit: January 09, 2007, 06:08:23 PM by Bubu74
»
Logged
COMODO user since January 2007
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 3628
I'm not grumpy, just misunderstood.
Re: Was I attacked?
«
Reply #1 on:
January 08, 2007, 11:45:46 AM »
Although an DDoS attack of some sort cannot be ruled out, it is more likely to be the P2P network that is generating this traffic. These incoming UDPs are likely to be other DC++ users trying to either identify what you are or just cataloging what you are sharing.
Logged
XP Pro+SP3 & CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very briefly.
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #2 on:
January 08, 2007, 07:55:03 PM »
Thank you for your answer!
Now, I have another question on the same subject. I am sorry to bother you with this, but I would like to learn the difference between the true attacks and the ordinary internet traffic...
During the period of 20 minutes, CPF logged more than 50 log entries. They are all the same (except for time, offcorse
):
Date/Time :2007-01-09 00:12:27
Severity :Medium
Reporter :Network Monitor
Description:Inbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Incoming
Source: 80.69.95.xxx
Destination: 192.168.2.101
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 9
During this time, the only application with access to the internet were Firefox and Thunderbird. Can someone please shed some light on this matter?
Logged
COMODO user since January 2007
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6003
Re: Was I attacked?
«
Reply #3 on:
January 09, 2007, 12:58:57 PM »
Have you done a search on the IP address from which these ICMP IN attempts were made? You can use a site like DNSStuff, to find out who the IP is.
Since it's an inbound request, all from the same IP (you said the only thing that varied was the time...), it should be pretty easy. That might help shed some light on it...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #4 on:
January 09, 2007, 02:07:31 PM »
Yes, I've checked the IP, it belongs to a
www.transip.nl
. It's a web hosting site (at least I think so) in the Nederlands.
Logged
COMODO user since January 2007
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6003
Re: Was I attacked?
«
Reply #5 on:
January 09, 2007, 02:59:42 PM »
And that's not a site/IP you're familiar with, I guess? You don't use them for anything, and it's not related to a torrent? (I know you said you only had FF and TB open at the time.) In which case it would look like it's an unsolicited communication...
You can add a Network rule, if you want, to specifically Block IP In from that IP address (or range of IPs, if you want to block them all...). In that rule, you can either block the ICMP protocol, or all IP protocol. If I knew that I had not in some way initiated the connection, I would probably block All IP protocols (ie, "Any").
Thus, your rule would be added to the Network Monitor above the bottom Block Rule, something like this:
Action = Block & Log
Protocol = IP
Direction = In
Source IP = The IP you want to block
Destination IP = Any
Details = Where IPProto is Any
If it persists, and you know that you are not initiating the contact, you can use the information from your CPF logs to contact your ISP, so that they can investigate and take appropriate action.
Hope that helps,
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #6 on:
January 09, 2007, 03:21:20 PM »
You're right, I've never contacted them, never heard of them, I don't even speak Dutch
.
I will block this site, and keep monitoring the logs. And if I see this happen again, I will report them.
Thank you very much for the advice!
Logged
COMODO user since January 2007
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6003
Re: Was I attacked?
«
Reply #7 on:
January 09, 2007, 04:14:40 PM »
Chances are, the IP address is being used as a sort of proxy for the originator of the contact, probably through the use of bots and whatnot. Technojargon stuff...
I say that to say, if you end up with a recurrent event, and wish to report to your ISP, I would not say that
www.transip.nl
was trying to hack you; I would report it that you are having an unexplained, unsolicited contact from the offending IP address, along with date/time info, etc.
Your ISP has an obligation to follow up on it, and should have better tools at their disposal for tracking down the source.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #8 on:
January 09, 2007, 04:45:48 PM »
It is very likely that it came from a proxy, but we will probably never know.
Hm, I was thinking about the rule you've posted earlier... isn't this kind of traffic already blocked by the default cpf Network rules?
And I can't figure out how did these ICMP traffic got past my router?
Logged
COMODO user since January 2007
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6003
Re: Was I attacked?
«
Reply #9 on:
January 09, 2007, 05:09:40 PM »
Quote from: Bubu74 on January 09, 2007, 04:45:48 PM
Hm, I was thinking about the rule you've posted earlier... isn't this kind of traffic already blocked by the default cpf Network rules?
And I can't figure out how did these ICMP traffic got past my router?
Yes, it is. I give you a gold star for noticing...
Here's the thought process:
1. It is currently blocked, because it's not explicitly allowed (ie, ICMP Port Unreachable is not allowed by the default rules), and the bottom Block and Log rule stops it.
2. CPF's rules filter from the top down, until the connection is either explicitly allowed or implicitly/explicitly denied.
3.
If
you left it as it is, and the "person" on the other end changed the IP protocol, it's possible (although not necessarily probable) that the connection might be allowed before it hits the bottom block rule.
4. By creating an explicit Block rule, rather than an implicit one, and moving it closer to the top of the hierarchy of Network Rules (ie, closer to Rule ID 0 ), you have a better chance of making sure it doesn't get thru by accident...
5. By having a separate Block & Log rule for the IP or IP range, you have a separate log entry; it may be easier to track that way.
As far as how it got past your router, well you'd have to access your router configuration and see what the deal is there. My guess is that ICMP is allowed for Pings, and there are probably some settings to tighten that aspect of it up.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #10 on:
January 09, 2007, 05:39:33 PM »
Quote from: Little Mac on January 09, 2007, 05:09:40 PM
Yes, it is. I give you a gold star for noticing...
Thanks!
Quote
Here's the thought process:
1. It is currently blocked, because it's not explicitly allowed (ie, ICMP Port Unreachable is not allowed by the default rules), and the bottom Block and Log rule stops it.
2. CPF's rules filter from the top down, until the connection is either explicitly allowed or implicitly/explicitly denied.
3.
If
you left it as it is, and the "person" on the other end changed the IP protocol, it's possible (although not necessarily probable) that the connection might be allowed before it hits the bottom block rule.
4. By creating an explicit Block rule, rather than an implicit one, and moving it closer to the top of the hierarchy of Network Rules (ie, closer to Rule ID 0 ), you have a better chance of making sure it doesn't get thru by accident...
5. By having a separate Block & Log rule for the IP or IP range, you have a separate log entry; it may be easier to track that way.
Thank you for explaining.
Quote
As far as how it got past your router, well you'd have to access your router configuration and see what the deal is there. My guess is that ICMP is allowed for Pings, and there are probably some settings to tighten that aspect of it up.
I will check it. The firewall is alredy set on High, but obviously needs some fine tuning...
Thanks again, you've been very helpfull!
Logged
COMODO user since January 2007
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6003
Re: Was I attacked?
«
Reply #11 on:
January 09, 2007, 05:44:21 PM »
No problem.
If you consider this to be fixed, you can Edit the Subject line of your first post in this topic (icon on the lower right, by your IP address), and add "[Resolved]" for other users' benefit.
If you want to wait a few days, to see what happens with the new Network Rule, and get your router figured out (someone here may be able to provide some input on that as well, even though it's not a Comodo thing...), or for some more follow up on this incident, that's fine as well.
We're glad to help.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Bubu74
Comodo Loves me
Offline
Posts: 177
Re: Was I attacked?
«
Reply #12 on:
January 09, 2007, 06:08:03 PM »
I think we can consider this case
closed
.
Logged
COMODO user since January 2007
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Was I attacked? [Resolved]
«
Reply #13 on:
January 09, 2007, 06:34:05 PM »
I will lock this topic.
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.138 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com