Re: advice about a worm intrusion alert



Joel Maslak wrote:
On 11/24/2006 at 11:03 AM, in message
<uTWSOL$DHHA.4620@xxxxxxxxxxxxxxxxxxxx>, Robert M
Jones<robert53newsgroups-ms2@xxxxxxxxxxxxxxxxx> wrote:
Security Alert - Medium Rick
Norton Internet Worm Protection has detected and blocked an intrusion attempt.
The text in More Info was as follows:
Intrusion: MS SQL PacketResolution DoS
Intruder: 192.168.1.1 (domain(53))
Risk Level: Medium.
Protocol: UDP
Attacked IP: COMPUTER NAME (192.168.1.2)
Attacked Port: ms-sql-m(1434)

Do you even have SQL installed on your machine? My guess is that you
don't.

As a result, port 1434 is not used by any specific program, but is
available for any program that needs a new UDP port to use.

Because of this, the DNS resolver is using it to make a DNS request
(your name server is probably set as 192.168.1.1). Your DNS server
responds to port 1434. However, Norton incorrectly classifies this as
an attack. It probably isn't.

That's sort of what I thought - but until I can be sure I did not want to give Norton any instructions to allow or remember - just saying "ok" when I get the block message.
Any advice on checking I can do (other than routine AV and spyware scans) most welcome.

--
Rev Robert M Jones, Wimborne Baptist Church, UK
http://www.wimborne-baptist.org.uk
Free trial of Mailwasher Pro - effective email spam filter - (commission
goes to our partners in Bulgaria)
http://fta.firetrust.com/index.cgi?id=420
.



Relevant Pages

  • Re: Telnet, Ping and Port 1025
    ... >>I do have Norton AV and Firewall installed, ... > outgoing packets for any particular port. ... > telnet server running and the port open to accept telnet ...
    (microsoft.public.security.virus)
  • Re: email not sending from Outlook 2003
    ... It's Norton AV 2009, ... I'll ask my email provider if port 587 is OK. ... So Norton changed your e-mail account settings but didn't change them ... So check if your e-mail provider also listens on port 587. ...
    (microsoft.public.outlook.general)
  • Re: NIS 2003 Help With
    ... Norton shows the IP Address to be mine ... NPF 02 we do not even show a port scan from Norton's ... > NIS 2003 rule allows the server to receive incoming ... > Try running the Norton web site test again. ...
    (comp.security.firewalls)
  • Re: Telnet, Ping and Port 1025
    ... >was Norton's own on-line security check that revealed the Telnet, Ping ... Norton doesn't seem, by default, to lock down all ports. ... outgoing packets for any particular port. ...
    (microsoft.public.security.virus)
  • Re: email not sending from Outlook 2003
    ... So, I'll be re-installing Norton Anti Virus, and we'll see ... Looks like Norton change the port so your e-mail client would connect to ... So Norton changed your e-mail account settings but didn't change them ... So check if your e-mail provider also listens on port 587. ...
    (microsoft.public.outlook.general)