Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-15-2006, 06:41 PM
blades1987@hotmail.com
Guest
 
Posts: n/a
Default Strange network probe activity

I have been receiving some interesting traffic across port 8000 and
3128 that I cannot identify the application making the probe:


Date: 11/15/2006
Time: 9:04:00 AM
Time Zone: -8:00
Source IP: 222.169.210.79
Source Port: 2370
Server IP: XXX.XXX.XXX.XXX
Server Port: 3128 (fomds)
Protocol: TCP

Bytes Sent: 0
Bytes Received: 223

GET http://bidhill.com/flashegg/prx.php?...y6u7i8o9p0*a-b
HTTP/1.0 Accept: */* Accept-Language: en-us User-Agent: Mozilla/4.0
(compatible; MSIE 6.0; Windows NT 5.0) Host: bidhill.com Connection:
Keep-Alive


Date: 11/15/2006
Time: 8:40:23 AM
Time Zone: -8:00
Source IP: 125.93.7.3
Source Port: 1252
Server IP: XXX.XXX.XXX.XXX
Server Port: 8000 (SHOUTcast)
Protocol: TCP

Bytes Sent: 0
Bytes Received: 191

GET http://tvcf.com.cn/mod/prx.php HTTP/1.0 Accept: */*
Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 6.0;
Windows NT 5.0) Host: tvcf.com.cn Connection: Keep-Alive

I am wondering if it is a virus probe from MyDoom or system probing for
an exploit in WinAmp. THe PHP file can be downloaded from the
bidhill.com website.


Reply With Quote
  #2 (permalink)  
Old 11-17-2006, 08:53 AM
Chris Kronberg
Guest
 
Posts: n/a
Default Re: Strange network probe activity

On 2006-11-15, blades1987@hotmail.com <blades1987@hotmail.com> wrote:
> I have been receiving some interesting traffic across port 8000 and
> 3128 that I cannot identify the application making the probe:

*snip*

Someone is looking for open proxy servers. The php scripts pipe
the results in a list for later usage.

Cheers,

Chris.


Reply With Quote
  #3 (permalink)  
Old 11-20-2006, 08:39 PM
blades1987@hotmail.com
Guest
 
Posts: n/a
Default Re: Strange network probe activity


Thanks, Chris. I am going to look at that PHP script again. The main
offenders look like they are launching probes from the Asia Pac net.

Again, thanks for your help.


Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Plan: Network Dlink & LInksys, on 2 network Wlan via WDS TJROCKSTAR Network Troubleshooting 2 02-21-2008 03:26 PM
WiMAX Forum News, Weekly Clip Report March 22-29, 2007 badger_b@hotmail.com alt.internet.wireless 0 03-31-2007 01:14 AM
Don't fall victim to the 'Free Wi-Fi' scam Ablang alt.internet.wireless 5 02-04-2007 08:44 AM
D-Link network - strange problem miffy alt.internet.wireless 2 11-14-2006 04:18 PM
[Job] Network Engineer - San Jose, CA toprecruiter alt.internet.wireless 2 10-20-2005 01:34 PM


All times are GMT. The time now is 12:57 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45