Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 16th, 2005, 01:57 PM
coolconman coolconman is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 83 coolconman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 20 h 18 m 34 sec
Reputation Power: 4
Exclamation Code Red Attacks on Netgear FVS318

I have a Netgear FVS318 VPN Router. Recently the log started showing a ton of messages similar to this:

2005-02-16 03:22:31 User.Info 192.168.199.20 [121765]:HTTP(80) Dest IP :65.19.192.77, Src IP :65.19.88.167
2005-02-16 03:22:31 User.Info 192.168.199.20 [121766]:TCP(1300) Dest IP :65.19.88.167, Src IP :192.168.199.21
2005-02-16 03:22:31 Daemon.Alert 192.168.199.20 Hacker Log[121767]:PROTO_TCP, SIP:65.19.88.167: 1300, DIP:65.19.192.77: 80, Code-Red
2005-02-16 03:22:32 Daemon.Alert 192.168.199.20 Hacker Log[121768]:PROTO_TCP, SIP:65.19.88.167: 1300, DIP:65.19.192.77: 80, Code-Red

I've been able to find 3 separate IP addresses that the dropped code reds are coming from. And although the source port changes quite often, the destination port is always 80. There seems to be a pattern though. The source port changes every seven drops. It also seems like on at least one of the IP's (65.19.88.167) there is a packet successfully going from my network to this address, then one coming back successfully to our webserver (192.168.199.21) before I get any dropped due to Code Reds. Is this a problem?

Reply With Quote
  #2  
Old February 16th, 2005, 02:17 PM
mitakeet's Avatar
mitakeet mitakeet is offline
Last Day: May 28, 2005
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2003
Location: Maryland
Posts: 4,575 mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level)mitakeet User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 9 h 51 m 4 sec
Reputation Power: 21
Since Code Red attacks IIS servers one would expect the destination port to be mostly 80 (of course you can attach a web server to any port). If the IPs are from computers you control you are the one infected. If they are from computers you know about, contact the owners and tell them to fix the damn things. If they are from anonymous machines, all you can do is wait until someone finally figures it out and kills it. Your router should be immune (boy I sure hope it is!), so other than spewing into your log file you should not have any problems.
__________________

Left DevShed May 28, 2005. Reason: Unresponsive administrators.
Free code: http://sol-biotech.com/code/.
Secure Programming: http://sol-biotech.com/code/SecProgFAQ.html.
Performance Programming: http://sol-biotech.com/code/PerformanceProgramming.html.

It is not that old programmers are any smarter or code better, it is just that they have made the same stupid mistake so many times that it is second nature to fix it.
--Me, I just made it up

The reasonable man adapts himself to the world; the unreasonable one persists in trying to adapt the world to himself. Therefore, all progress depends on the unreasonable man.
--George Bernard Shaw

Reply With Quote
  #3  
Old February 16th, 2005, 07:44 PM
coolconman coolconman is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 83 coolconman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 20 h 18 m 34 sec
Reputation Power: 4
Thanks alot Mitakeet

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Code Red Attacks on Netgear FVS318


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway
Stay green...Green IT