Lowyat.NET Forums

Welcome Guest ( Log In | Register )

LYN wins Intel-Lenovo-Tangs Blogathon challenge. Thank you everybody!
 
RSS feedBump TopicClosed TopicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> Weird activity

mai-k
post Dec 1 2006, 11:50 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #1


Getting Started
**

Group: Junior Member
Posts: 291
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003





user posted image

Above - firewall turned off
Below - firewall turned on

I notice port 135 on my laptop is open. Is it normal?
Who is the person on 218.111.4.57?
Tmnet people doing their duty or someone trying to gain access?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
azmihamzah
post Dec 1 2006, 11:57 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #2


I love Nikon
*****

Group: Senior Member
Posts: 856
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2006
From: شه عالم






do you turn on your p2p program?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
nwk
post Dec 1 2006, 11:58 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #3


Getting Started
**

Group: Junior Member
Posts: 188
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Sep 2006
From: East of Eden





tmnut is scanning your pc. you better hope your firewall is up, or else...........
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mai-k
post Dec 1 2006, 12:00 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #4


Getting Started
**

Group: Junior Member
Posts: 291
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003





QUOTE(azmihamzah @ Dec 1 2006, 11:57 AM)
do you turn on your p2p program?
*


No P2P running. I only surf net.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
scarred
post Dec 1 2006, 12:09 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #5


Getting Started
**

Group: Junior Member
Posts: 259
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003




Port 135 can be exploited by the hackers. Defaulted to Open in Windows.

That IP is within the Streamyx Users, maybe its from a streamyx user dat didn't realize he had a virus, or simply one of the scriptkiddies.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Zephro
post Dec 1 2006, 01:39 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #6


Getting Started
**

Group: Junior Member
Posts: 144
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Nov 2005
From: The land of moe. And KL.




I get that all the time as soon as I log on. Always blocked by Kaspersky. Seems like a lot of Msian users have been secretly rooted.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
evilguy
post Dec 1 2006, 02:15 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #7


Enthusiast
*****

Group: Senior Member
Posts: 848
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Dec 2004




can explain how to check all of that? like thread starter post at 1st post
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
adewhite
post Dec 1 2006, 10:44 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #8


Getting Started
**

Group: Junior Member
Posts: 92
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2006
From: Kuala Lumpur





Just type netstat at command line.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Salamander
post Dec 2 2006, 12:27 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #9


Newbie
*

Group: Junior Member
Posts: 11
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003




It's probably:
a) someone doing a subnet scan to find vulnerable computers [using rpc dcom exploit blah blah blah]
b) or someone that's already been infected by a trojan and it's looking for open hosts etc

In any case being fully patched doesn't always guarantee safety, which is why firewalls are important but there is always other ways of getting hit by stuff like this. I've done done tests on an open windows box and it was infected within 1-5 mins of putting it online, it always peaks when there are new exploits out or no patches hehe. You'll always be seeing traffic like that as there are alot of unpatched computers in Malaysia and this kind of thing is quite rampant in the country [I see alot of vulnerable Malaysian hosts that are usually used as drones or spambots for irc etc].
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Bump TopicClosed TopicTopic OptionsStart new topic
 



----debug section please ignore----
Lo-Fi Version Time is now: 24th November 2009 - 03:59 PM
All Rights Reserved 2003-2009 Vijandren Ramadass (~living on a prayer~)