There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot browser bsod computer cpu crash css dell desktop driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware missing monitor network networking outlook outlook 2003 outlook 2007 outlook express password popups problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
Any Thoughts on These Disturbing Probes?


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
Anchoret's Avatar
Senior Member with 172 posts.
 
Join Date: Jan 2006
Location: California
10-Nov-2007, 02:41 PM #1
Any Thoughts on These Disturbing Probes?
"Port 31113 is a known vulnerability hole in Windows DNS servers and port 1026 is the vulnerability hack...Microsoft remote administrative privileges allow 'backdooring' into Microsoft operating systems via IP/TCP ports 1024 through 1030.

"DoD is the US Department of Defense, USAIC is the US Army Information Systems Command. The Australian Department of Defense, IBM, Intel, AT&T and Emirates Telecom are known NSA SIGINT proxies and contractors."

I also got similar pokes from Halliburton, NASA and the UKMoD. Identical probes are reported elsewhere on the Internet.

Here are the logs. Thoughts?

2007-11-08 01:28:22;AT&T Global Network
Services;32.131.37.13:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08 02:18:11;Emirates Telecommunications
Corporation;195.229.200.93:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08
03:17:51;USAISC;160.139.84.197:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08 19:23:54;Intel
Corporation;192.198.162.254:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 19:47:21;IBM
Corporation;9.184.117.29:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:06:01;Australian Department of
Defence;146.221.50.105:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:12:35;USAISC Eastern
Area;144.105.17.244:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:29:10;DoD Network Information
Center;29.214.246.94:31138;xxx.xxx.107.108:1026;UDP;Blocked
Anchoret's Avatar
Senior Member with 172 posts.
 
Join Date: Jan 2006
Location: California
11-Nov-2007, 11:38 AM #2
Awfully quiet in here all of a sudden.
wk2000's Avatar
Senior Member with 283 posts.
 
Join Date: Sep 2007
Experience: Intermediate
11-Nov-2007, 03:19 PM #3
My guess is those various computers are compromised PCs or are part of a botnet. I dont think the Austrailian Dept of Defence will be interested in breaking into your computer.
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 07:02 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.