Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 3rd, 2003, 10:19 AM
Douglas
 
Posts: n/a
Default Strato.net

Hi ,
For a few days I've been getting bombarded with incoming Echo Requests from strato.net. It's basically constant.
I looked at their web page, and can't figure out why they would be doing this. I've never been there before.
Can any one explain this to me?

Thanks,
Douglas
  #2  
Old December 3rd, 2003, 09:29 PM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,525
Default Re:Strato.net

Hi Douglas,

I know you've stated what appears to be a complete description of the occurrence, however it is always helpful to actually include several examples right from the full firewall log. Sometimes there is some small and subtle thing that the log will show that isn't readily apparant from a text description.
  #3  
Old December 4th, 2003, 06:22 PM
Douglas
 
Posts: n/a
Default Re:Strato.net

Hi LWM,
Thanks for responding.
The traffic has died down quite a bit, but it's still happening. The log is for about 10 minutes. This is now fairly normal.
BTW, I googled about echo requests, trying to learn, but I didn't do a very good job. All I really saw was a claim that worms on other people's computers can cause this. True?

Regards,
Douglas
Attached Images
 
  #4  
Old December 4th, 2003, 07:40 PM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,525
Default Re:Strato.net

Yes, that is most probably (+99% likely) Worm related activity. The worm Nachi (aka. Welchia, and other names) has been out a few months now. The way it usually works is after infecting a system, it pings other systems in the same network range looking for other systems to infect. It use an RPC DCOM exploit to get into systems that have that running, not patched to the specific vulnerability and which are unprotected by any firewall mechanism.

Notice that the source addresses are all (mostly) different. It isn't strato.net (as in the web server at that name) that is doing this, it is individual users at different IP addresses (probably customers of theirs if they are an ISP).

Here's some reading on the worm:

http://www.sophos.com/virusinfo/analyses/w32nachia.html
  #5  
Old December 4th, 2003, 10:09 PM
Douglas
 
Posts: n/a
Default Re:Strato.net

Many thanks LWM. Much clearer now.
Best Regards,
Douglas
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:54 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums