Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod crash desktop dns driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop mac malware memory monitor motherboard network not working printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Any Thoughts on These Disturbing Probes?

Reply  
Thread Tools
Anchoret's Avatar
Member with 239 posts.
 
Join Date: Jan 2006
Location: California
10-Nov-2007, 03:41 PM #1
Any Thoughts on These Disturbing Probes?
"Port 31113 is a known vulnerability hole in Windows DNS servers and port 1026 is the vulnerability hack...Microsoft remote administrative privileges allow 'backdooring' into Microsoft operating systems via IP/TCP ports 1024 through 1030.

"DoD is the US Department of Defense, USAIC is the US Army Information Systems Command. The Australian Department of Defense, IBM, Intel, AT&T and Emirates Telecom are known NSA SIGINT proxies and contractors."

I also got similar pokes from Halliburton, NASA and the UKMoD. Identical probes are reported elsewhere on the Internet.

Here are the logs. Thoughts?

2007-11-08 01:28:22;AT&T Global Network
Services;32.131.37.13:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08 02:18:11;Emirates Telecommunications
Corporation;195.229.200.93:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08
03:17:51;USAISC;160.139.84.197:31113;xxx.xxx.107.83:1026;UDP;Blocked

2007-11-08 19:23:54;Intel
Corporation;192.198.162.254:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 19:47:21;IBM
Corporation;9.184.117.29:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:06:01;Australian Department of
Defence;146.221.50.105:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:12:35;USAISC Eastern
Area;144.105.17.244:31139;xxx.xxx.107.109:1026;UDP;Blocked

2007-11-08 21:29:10;DoD Network Information
Center;29.214.246.94:31138;xxx.xxx.107.108:1026;UDP;Blocked
Anchoret's Avatar
Member with 239 posts.
 
Join Date: Jan 2006
Location: California
11-Nov-2007, 12:38 PM #2
Awfully quiet in here all of a sudden.
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
11-Nov-2007, 04:19 PM #3
My guess is those various computers are compromised PCs or are part of a botnet. I dont think the Austrailian Dept of Defence will be interested in breaking into your computer.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:50 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.