Re: Interesting traffic problem



On Fri, 29 Dec 2006, in the Usenet newsgroup comp.os.linux.networking, in
article <08WdnVI28Ph-ewnYnZ2dnUVZ_vOlnZ2d@xxxxxxxxxxx>, tiffini wrote:

I have a befsr41 router with snmp :-) So I can log traffic going into
my little network using wallwatcher and opmanager.

It gives you something to watch, I suppose. You'd actually learn a lot
more by using a packet sniffer, as most of this traffic is in plain ASCII
and quite readable.

I have one XP machine I leave on a lot.

but you never looked at the traffic from a newly installed but isolated
windoze box. They chatter a lot, even before they get infected.

I notice that it is sending UDP outbound from L-port 137 to R-port 137.

netbios-ns 137/tcp NETBIOS Name Service
netbios-ns 137/udp NETBIOS Name Service

Then in a relatively short amount of time I see an inbound request from
a different IP to ports 1026 ,1027, and 1028 from a different IP that
the 137 was sent from.

That's why the packet sniffer would be useful. You'd see that the packets
contain faked windoze warning messages - telling you that your XP box has
discovered $RANDOM_NUMBER of problems with the registry, or some bunch of
bull droppings, and that you need to go to some spam site to get your
registry repaired. It's some spammer sending messenger spam. Blindingly
obvious clue: the web site has nothing to do with microsoft (who could
possibly care less if your windoze box gets 0wn3d). It's all part of
the benefits you get as a result of incompetent programming by the klowns
in Redmond.

I have norton's running, and ad aware and spybot don't show anything.

Yes, the anti-malware stuff assumes you already know you've got windoze
installed. Why else would you be using their stuff?

The addresses seem to come from anywhere China, hong kong, even the US
and Canada.

Most of them are faked - UDP doesn't need a two way conversation to
deliver the windoze spam. Again, a packet sniffer would show more
interesting details in the headers of those packets. The supposed
source addresses are random numbers, which shows up as occasional
addresses that haven't even been allocated by IANA, much less one of
the five Regional Internet Registries (AFRINIC, APNIC, ARIN, LACNIC or
RIPE).

Block _ALL_ UDP coming in that is not responses from your ISP's name
servers (source port 53 to some high port that had just sent out a
request a second or so before). If you are getting DHCP service from
your ISP, you need UDP ports 68 OUTbound to 67, and the replies from
port 67 back to your 68. If you use a *nix version of traceroute (but
not the b0rken windoze imitation), then you need ports 33434 to about
33480 open. Otherwise you _probably_ don't need any UDP, and can just
drop it into the bit.bucket at your perimeter.

As for your port 137 traffic, it's only windoze trying to be helpful
and share everything with anyone. Microsoft figured you (or at least
somebody) might find it useful.

Old guy
.



Relevant Pages

  • Re: Another source other than KRNIC?
    ... If you are talking about windoze messenger spam, ... drop UDP to those ports. ... logging to see what's out there, but the firewall is working, so who cares. ...
    (comp.security.firewalls)
  • Re: OT: Zone Alarm - Is This True?
    ... I'd suspect that the original reason for a firewall pgm to contact a central server would be to post information on attack types. ... If you wish to stay in the OS, start Windoze in console safe mode and wander around using DOS style commands, set the attributes of the file to non system, non hidden and then delete it. ... The directory gives the first cluster where to find the file and the total file length. ... - One of the major difference in the basic firewalls between Linux and Windoze has been that iptables Linux based ones only tend to block specific ports, whereas Windoze ones tend to associate a port with application block. ...
    (uk.radio.amateur)
  • RE: forcdos.exe, msagent directory, DOS or warez??
    ... Consider installing an emergency copy of Windoze, ... forcdos.exe, msagent directory, DOS or warez?? ... massive activity was found on ports 63501, 63502, 1734 and other high range ... Firstly does anyone have any advice on how to get to this exe file? ...
    (Security-Basics)
  • Re: Linux Replacing Windows on the Desktop, I Think Not! (was Re: Same concerns as a real American)
    ... >> concern for OS quality or capabilities. ... Windoze + generic PC hardware was cheaper than the Mac OS + ... Interesting ports on: ... 137/tcp filtered netbios-ns ...
    (comp.os.linux.misc)
  • Re: possible rooted systems
    ... the software we run that have very dynamic port usage, ... some computers are using said ports. ... Its been determined we need a packet sniffer for the job that works on novell ... Kyle ...
    (Security-Basics)