Re: advice about a worm intrusion alert



Port 1434 is the SQL Browser service used for locating SQL Servers.

I would NOT allow Ports 1434 or 1433 to be open to the outside.

Is this a NAT router directly connected to your DSL/Cable modem?

--
Arnie Rowland, Ph.D.
Westwood Consulting, Inc

Most good judgment comes from experience.
Most experience comes from bad judgment.
- Anonymous

You can't help someone get up a hill without getting a little closer to the
top yourself.
- H. Norman Schwarzkopf


"Robert M Jones" <robert53newsgroups-ms2@xxxxxxxxxxxxxxxxx> wrote in message
news:uTWSOL$DHHA.4620@xxxxxxxxxxxxxxxxxxxxxxx
XP Home, limited user account. Newbie to this group - I know next to
nothing about ports but am an experienced computer user otherwise.
Can anyone interpret this for me - just started to get these recently -
this is only the second one. Got it while using a user account in my XP
Home machine.

Security Alert - Medium Rick
Norton Internet Worm Protection has detected and blocked an intrusion
attempt.
The text in More Info was as follows:
Intrusion: MS SQL PacketResolution DoS
Intruder: 192.168.1.1 (domain(53))
Risk Level: Medium.
Protocol: UDP
Attacked IP: COMPUTER NAME (192.168.1.2)
Attacked Port: ms-sql-m(1434)

The Intruder address was my router, to which one Win98SE computer is
connected by ethernet (not mentioned in report) and the other on the
192.168.1.2 address is my XP Home machine, wirelessly connected to the
router.

I clicked OK and then the wireless connection lost its IP and
connectivity - and I had no internet access on the wireless XP machine.
Router was still connected to internet fine - all lights glowing properly.

Computer upstairs 192.168.1.3 was on and could connect to the internet -
no one was using it at the time of the alert. It has Zone Alarm free
version to prevent any outgoing stuff, and also NAV and Spybot S&D
resident (teatimer). It is on Win98SE. No alerts showing.

This machine runs Windows XP Home (user account) has NAV, Counterspy and
Zone Alarm free. Wireless network is WPA-PSK with 63 character pw.

Log off and on did not restore the wireless (always does usually).
Log off and then on to Admin acct - again wireless network did not work
but I got a windows error - windows is recovering from a serious error.
Still no connection.

Did a warm reboot and then everything was back to normal.

I do a Norton AV and Counterspy scan daily. Clear.

I think all the Windows/wireless hassle was due to the Norton blocking the
request, and I think the "intrusion" was legitimate - but I don't want to
"allow" it unless someone can explain the details to me. Many thanks to
any network gurus who can interpret please.

--
Rev Robert M Jones, Wimborne Baptist Church, UK
http://www.wimborne-baptist.org.uk
Free trial of Mailwasher Pro - effective email spam filter - (commission
goes to our partners in Bulgaria)
http://fta.firetrust.com/index.cgi?id=420


.



Relevant Pages

  • Re: Two wireless routers wired together
    ... Then, on my floor, I connect my wall socket to my router, a Linksys ... connect the wall socket to the Uplink port of my BEFW11S4. ... not want me to use his wireless connection, so I need some way to get ... connection. ...
    (alt.internet.wireless)
  • Re: Opening a SQLExpress database (Desktop) from PocketPC
    ... port it's running under ... > i can't even get a basic connection to my SQLExpress...!?!? ... > - using XP Pro desktop and can communicate to SQL Express via SQL Server ... >> When you specify the AttachDBFileName in the Compact Framework ...
    (microsoft.public.sqlserver.ce)
  • Re: home network
    ... disconnect the ADSL router modem from the desktop USB ... port and replace the connection with a USB wireless adapter, ...
    (microsoft.public.windowsxp.network_web)
  • Re: Cannot connect to SQL express database ????
    ... Frist of all I forgot to open the port 1500 in my windows firewall. ... normally with SQL server. ... This connection string using sytax ... have made many connection like that with SQL server ...
    (microsoft.public.sqlserver.connect)
  • Re: SQL Err when WLAN conn is dropped and then restored. Help!
    ... We run ppc's in our warehouse that communicate via wireless lan with our SQL ... Server 2000 database. ... lose their wireless connection. ...
    (microsoft.public.dotnet.framework.compactframework)