Re: advice about a worm intrusion alert



On 11/24/2006 at 11:03 AM, in message
<uTWSOL$DHHA.4620@xxxxxxxxxxxxxxxxxxxx>, Robert M
Jones<robert53newsgroups-ms2@xxxxxxxxxxxxxxxxx> wrote:
Security Alert - Medium Rick
Norton Internet Worm Protection has detected and blocked an
intrusion
attempt.
The text in More Info was as follows:
Intrusion: MS SQL PacketResolution DoS
Intruder: 192.168.1.1 (domain(53))
Risk Level: Medium.
Protocol: UDP
Attacked IP: COMPUTER NAME (192.168.1.2)
Attacked Port: ms-sql-m(1434)

Do you even have SQL installed on your machine? My guess is that you
don't.

As a result, port 1434 is not used by any specific program, but is
available for any program that needs a new UDP port to use.

Because of this, the DNS resolver is using it to make a DNS request
(your name server is probably set as 192.168.1.1). Your DNS server
responds to port 1434. However, Norton incorrectly classifies this as
an attack. It probably isn't.
.



Relevant Pages

  • Re: Intrusion Attempts ?
    ... It probably is an intrusion attempt, but nothing to worry about, as long as ... What some hacker here has done here, is attempted to connect to a large ... and attempt a dictionary realy attack on port 25. ... >I have a SBS2000 system and daily receive the following ISA server ...
    (microsoft.public.windows.server.sbs)
  • Re: Firewire drive disappears
    ... Firewire cable too long, in vicinity of RF intrusion, or defective. ... My external LG SuperMulti RW dvd drive connected to ... firewire IEEE 1394 port often just disappears. ...
    (microsoft.public.windowsxp.hardware)
  • Re: Malicious use of grc.com
    ... > port scans in question HAVE a valid IP...his systems ... I think Gibson fully understands this...and he also ... information returned from a port scan to then attack ... > defined by me as attacks or intrusion attempts? ...
    (Vuln-Dev)
  • Firewall Detected TCP Xmas Scan???
    ... My firewall caught this (TCP Xmas Scan) as an intrusion ... attempt today on port 8888. ...
    (microsoft.public.security)