RE: Stopping Admin Alert SPAM

From: Jay Lagorio (jay@lagorio.net)
Date: 01/23/03

  • Next message: Michael Katz: "Re: Stopping Admin Alert SPAM"
    Date: Thu, 23 Jan 2003 13:47:29 -0500
    From: "Jay Lagorio" <jay@lagorio.net>
    To: "Ed Sunder" <edsunder@3hd.com>, <focus-ms@securityfocus.com>
    

    I blocked port 135 (TCP/UDP) at the firewall...haven't seen another one since.

    --Jay Lagorio
    http://www.lagorio.net/

    -----Original Message-----
        From: "Ed Sunder" <edsunder@3hd.com>
        Sent: 1-23-2003 11:45:43 AM
        To: "focus-ms@securityfocus.com" <focus-ms@securityfocus.com>
        Subject: Stopping Admin Alert SPAM
        
        Okay, I haven't found a good answer to this online and would appreciate
        any advice this group has... Our servers are being deluged with Admin
        Alert Spam's. At a certain point, particularly over a weekend, with no
        one actively looking at the machine, if there are enough messages it can
        cause some services to shut down. I read that blocking ports 137-139
        would stop these messages, but I did that in our firewall and yet the
        messages still came.
        
        I'm wondering:
        1) If I disable the messenger service on the server, could there be any
        bad ramifications of that, other than potentially not receiving
        legitimate messages about system shutdowns etc.? Also, would that stop
        the problem?
        2) Is there some other way to stop these messages? Are they coming in on
        another port etc.?
        
        Any help on this would be appreciated.
        Thanks in advance,
        
        Ed Sunder
        Three HD
        



    Relevant Pages

    • Re: [opensuse] Remote upgrade problem
      ... All my remote sites have serial console servers connected. ... CCM840 8 port, dedicated local console ...
      (SuSE)
    • Re: Blocking attacks from spoofed IP addresses
      ... cause a _Self_ Denial Of Service attack. ... Defeating Denial of Service Attacks ... of our DMZ servers, and had source IPs from our public DNS servers. ... Web services are on your port 80 and/or 443, ...
      (comp.os.linux.networking)
    • panic: page fault - 6.0-RELEASE-p7
      ... While we thought we had done enough testing, apparently we hadn't and are now experiencing panic's on a number of the servers. ... ppc0: parallel port not found. ... unknown: can't assign resources (memory) ...
      (freebsd-questions)
    • Re: panic: page fault - 6.0-RELEASE-p7 (now 6.1-RC2)
      ... While we thought we had done enough testing, apparently we hadn't and are now experiencing panic's on a number of the servers. ... It has shown that information before, and it has always been tcpserver from the ucspi-tcp-0.88_2 port. ... unknown: can't assign resources (memory) ...
      (freebsd-questions)
    • Is FreeBSD ready for desktop (Mozilla Flash)
      ... monitor,, somehow the install fails to detect ... "Macromedia Flash plugin is not available for FreeBSD. ... I quote again "Install the www/linuxpluginwrapper port. ... servers, ...
      (comp.unix.bsd.freebsd.misc)