Please help with this strangeness

From: Michael Thompson (mike_at_thompsonmike.co.uk)
Date: 01/15/04

  • Next message: Andrew Leung: "RE: Windows Remote Desktop"
    Date: Thu, 15 Jan 2004 03:03:20 +0000
    To: security-basics@securityfocus.com
    
    
    

    Hi Security-basics,

    I was going through all my security logs today and I noticed something
    a little odd, and wonderd if anyone could offer any insight? I am not
    that good at detailed security!

    I have a IPBlock assigned from my ISP, where 81.174.224.68 to
    81.174.224.70.

    As I understand it, 68 is a broadcast address, 69 is assigned to the
    router, 70 is for a server, which I dont use at the present time.

    Now, in my snort logs, which is connected to the outside of the
    firewall I get the following logs..

    [**] [1:483:2] ICMP PING CyberKit 2.2 Windows [**]
    [Classification: Misc activity] [Priority: 3]
    01/15-02:49:35.625784 81.174.224.69 -> 81.174.224.70
    ICMP TTL:111 TOS:0xA0 ID:45600 IpLen:20 DgmLen:92
    Type:8 Code:0 ID:512 Seq:52213 ECHO
    [Xref => http://www.whitehats.com/info/IDS154]

    [**] [1:483:2] ICMP PING CyberKit 2.2 Windows [**]
    [Classification: Misc activity] [Priority: 3]
    01/15-02:49:35.641759 81.174.224.69 -> 81.174.224.68
    ICMP TTL:110 TOS:0xA0 ID:45598 IpLen:20 DgmLen:92
    Type:8 Code:0 ID:512 Seq:51701 ECHO
    [Xref => http://www.whitehats.com/info/IDS154]

    [**] [1:483:2] ICMP PING CyberKit 2.2 Windows [**]
    [Classification: Misc activity] [Priority: 3]
    01/15-02:49:35.642071 81.174.224.69 -> 81.174.224.70
    ICMP TTL:110 TOS:0xA0 ID:45600 IpLen:20 DgmLen:92
    Type:8 Code:0 ID:512 Seq:52213 ECHO
    [Xref => http://www.whitehats.com/info/IDS154]

    [**] [1:483:2] ICMP PING CyberKit 2.2 Windows [**]
    [Classification: Misc activity] [Priority: 3]
    01/15-02:49:35.649566 81.174.224.69 -> 81.174.224.71
    ICMP TTL:111 TOS:0xA0 ID:45601 IpLen:20 DgmLen:92
    Type:8 Code:0 ID:512 Seq:52469 ECHO
    [Xref => http://www.whitehats.com/info/IDS154]

    [**] [1:483:2] ICMP PING CyberKit 2.2 Windows [**]
    [Classification: Misc activity] [Priority: 3]
    01/15-02:49:35.665945 81.174.224.69 -> 81.174.224.71
    ICMP TTL:110 TOS:0xA0 ID:45601 IpLen:20 DgmLen:92
    Type:8 Code:0 ID:512 Seq:52469 ECHO
    [Xref => http://www.whitehats.com/info/IDS154]

    Now, I thought of welchia or one of its many variants, and all
    machines are clean, the DHCP records show only one machine on the
    network connected mostly, thats my machine. It's clean.

    What could be causing these broadcasts? Any one have any ideas?

    -- 
    Best regards,
     Michael (mike@thompsonmike.co.uk)
       
    Join the American Non-Sequitur Society -- we don't make sense, but we do like pizza. 
    http://www.thompsonmike.co.uk/
    PGP KeyID := 0xA9547E32
    'To see a world in a grain of sand
    And heaven in a wild flower
    To hold infinity in the palm of your hand
    And eternity in an hour'
    Using TheBat! Version 2.02.3 CE
    Running On Windows XP (2600, Service Pack 1)
    Sent From OneAndOne
    
    



  • Next message: Andrew Leung: "RE: Windows Remote Desktop"

    Relevant Pages

    • Re: unaccesible system event log
      ... Sophos EM Library is one part of antivirus solution for distributing ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you get ...
      (microsoft.public.windows.server.active_directory)
    • Re: The security log on this system is full
      ... Even I clear the event security logs, the error disappears during some days ... I wouldn't set to ''1'' because it will crash my server. ...
      (microsoft.public.security)
    • Re: unaccesible system event log
      ... antivirus protection Sophos to workstations. ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
      (microsoft.public.windows.server.active_directory)
    • Re: unaccesible system event log
      ... "Al Mulnick" wrote: ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
      (microsoft.public.windows.server.active_directory)
    • Re: Analyse der Security Logs (DCs)
      ... > ich suche Produkte zur Analyse von Security Logs. ... wäre MOM eine Möglichkeit. ... jedoch out-of-the-box keine Regeln für die Analyse von Security Logs, ...
      (microsoft.public.de.german.win2000.active_directory)