Re: Security question - please advise!

From: Don Kelloway (dkelloway_at_commodon.com)
Date: 09/30/04


Date: Thu, 30 Sep 2004 00:42:09 GMT


"Weeble" <nono@hotmail.com> wrote in message
news:MhSdnVH8cOvHHsfcSa8jmA@karoo.co.uk...
> Do I need to worry that Sygate Personal Firewall is logging hundreds of
> 'Major' intrusions like this:
>
> [215] Outgoing LSASS buffer overflow exploit attempt detected.
>
> % This is the RIPE Whois secondary server.
> % The objects are in RPSL format.
> %
> % Rights restricted by copyright.
> % See http://www.ripe.net/db/copyright.html
>

If you are referring to hundreds of 'incoming' connection attempts to TCP
port 445, then the answer is no. You should not have anything to be
concerned with as this merely indicates external (compromised) systems
attempting to spread a worm, etc.

If however you are referring to hundreds of 'outgoing' connection attempts
to TCP port 445, then the answer is yes. You most definitely have something
to be concerned with as it indicates your system has probably become
compromised with a worm attempting to spread itself. For this you will need
to immediately remove your system from the LAN and begin the process of
identification and removal.

-- 
Best regards, from Don Kelloway of Commodon Communications
Visit http://www.commodon.com to learn about the "Threats to Your Security 
on the Internet". 


Relevant Pages

  • Code-Red: An analytic model of its spread
    ... Subject: Code-Red: An analytic model of its spread ... and then try to compromise that IP address using ... the worm analyzed by Eeye has what seems like a bug. ... compromised machine picks other machines to attack completely at random. ...
    (Incidents)
  • greatly suppress this historic yarn
    ... My filthy watch won't wrap before I creep it. ... Almost no complex sum or market, ... We spread them, then we exactly arrive Pilar and Isabelle's firm ... Tell Talal it's static modifying down a connection. ...
    (sci.crypt)
  • Re: linksys wrt54g router seems to leak.
    ... unsolicited connection to TCP port 1862 on your computer. ... Has your router been hacked-- if you login to its admin ... The doc says this router does the stateful packet inspection. ...
    (comp.security.firewalls)
  • Re: LSA Shell (Export Version) - System Shutdown
    ... you establish an internet connection and have not enabled a firewall. ... your PC running Windows XP has indeed contracted the Sasser worm. ... What You Should Know About the Sasser Worm and Its Variants ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: JSH: Not typical people
    ... land it. ... casts Susie, it swears Morris instead. ... He'll be proposing in connection with educational Sadam until his ... spread very heavily? ...
    (sci.crypt)