RE: Weird Traffic from www.eyeblaster-bs.com

From: Cushing, David (David.Cushing_at_hitachisoftware.com)
Date: 05/30/03

  • Next message: Jeff Adams: "RE: strange cmd.exe access"
    Date: Fri, 30 May 2003 11:39:28 -0400
    To: "Jeremy Junginger" <jj@act.com>, <incidents@securityfocus.com>
    

    Can't explain your traffic, but your description doesn't sit quite right. Did you really see a Syn to internal port 80 from these folks? Or did you just see traffic with port 80 as a destination? A client can use port 80 to initiate a connection. I'm betting that's all you saw. Logs?

    Eyeblaster is an ad server...
    http://www.eyeblaster.com/WebSite/default.htm

    I guess bs (in this case) stands for Burst Server.

    From google:
    http://www.ufoot.org/misc/plague/ads.php3
    http://ssmedia.com/Utilities/hosts/

    Doesn't sound like something to get worked up over. Why not block them and save your users a few ads, heh heh.

    -David

    > -----Original Message-----
    > From: Jeremy Junginger [mailto:jj@act.com]
    > Sent: Thursday, May 29, 2003 5:45 PM
    > To: incidents@securityfocus.com
    > Subject: Weird Traffic from www.eyeblaster-bs.com
    >
    >
    > Good Afternoon,
    >
    > I am seeing some strange traffic from www.eyeblaster-bs.com on both
    > network and host based IDS. More specifically, I'm seeing TCP port 80
    > (http) traffic from multiple internal clients to
    > http://www.eyeblaster-bs.com/BurstingPipe and
    > http://www.eyeblastrer-bs.com/BurstingPipe.asp?param=% . So far, it
    > looks like normal surfing....well...almost. The strange
    > thing is that I
    > have seen traffic that appears to be sourced from this server
    > to clients
    > (dest port 80) on the Internal Network (which should be relatively
    > protected as they use Port Address Translation, not to
    > mention that port
    > 80 is not allowed to those client machines). I've seen this URL
    > mentioned on several usage reports, but have not seen any explanations
    > about what it is. Let me know what you think.
    >
    > Here are some of the other networks that have seen traffic TO this
    > server:
    > http://www.olc.edu/~bbump/usage/ns1/7th/url_200211.html
    > http://network.ci.seekonk.ma.us/WebUsage/Library/url_200212.html
    > http://www.bsafehome.com/historyreport.asp
    >
    >
    > -Jeremy
    >
    > These are not the packets you're looking for...You can go about your
    > business.....Move along....
    > :-)
    >
    > --------------------------------------------------------------
    > --------------
    > --------------------------------------------------------------
    > --------------
    >
    >

    ----------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Jeff Adams: "RE: strange cmd.exe access"

    Relevant Pages

    • RE: Printing from Win9x clients stops
      ... > and make sure this software does not interfere with SBS Server. ... > clients, please disable it and try again. ... Create a local printer and redirect the port to the network server. ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA Server & a WiFi Hotspot (some DHCP for good measure too)
      ... ISA2k4 is currently not supported on SBS ... To review - you have LAN clients that you want to have ... card for your server. ... > network with 5 client computers. ...
      (microsoft.public.windows.server.sbs)
    • RE: Users Cant Access Documents on Server
      ... Thanks for using the SBS newsgroup. ... As well as we know, if a workstation would not access network shares, then ... Leave the Default Gateway of the internal NIC blank of the server box. ... Clients That Require SMB Signing ...
      (microsoft.public.windows.server.sbs)
    • Re: Using Remote Desktop From an SBS Domain
      ... I should say bypassing my server not the router. ... Right click My Network Places...Properties. ... Internet connection, bypassing my SBS/ISA network all together. ... the port number you connect to from 80 to a port of your ...
      (microsoft.public.windows.server.sbs)
    • ie 6.0
      ... > laptop moves from one network to another, its IP address lease might need ... > request might go to a different server that will not extend the lease ... > for a period of time, it will not provide the time to requesting clients. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)