Announcement

Collapse
No announcement yet.

Strange whats this???

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Strange whats this???

    Just rebooted the machine after installing ATI drivers and the first error was cannot reconnect network drive.

    This machine doesn't map too any network drives. It holds shares for my other machine and thats it.

    I then ran netstat from the command line

    I found this oddity 212.23.37.32:http Fin_Wait_1

    What ???

    I looked it up and got the following

    % This is the RIPE Whois secondary server.
    % The objects are in RPSL format.
    %
    % Rights restricted by copyright.
    % See http://www.ripe.net/db/copyright.html

    inetnum: 213.23.0.0 - 213.23.71.255
    netname: ARCOR-DSL-NET3
    descr: ARCOR AG
    descr: Alfred-Herrhausen-Allee 1
    descr: D-65760 Eschborn
    descr: Germany
    country: DE
    admin-c: ANOC1-RIPE
    tech-c: ANOC1-RIPE
    rev-srv: ns1.arcor-ip.net
    rev-srv: ns2.arcor-ip.net
    rev-srv: ns3.arcor-ip.net
    status: ASSIGNED PA
    notify: ip-registry@arcor.net
    mnt-by: ARCOR-MNT
    changed: ip-registry@arcor.net 20030623
    source: RIPE

    route: 213.23.0.0/17
    descr: Mannesmann Arcor Telecommunications AG & Co
    descr: Germany
    origin: AS3209
    notify: ip-registry@arcor.net
    mnt-by: ARCOR-MNT
    changed: ip-registry@arcor.net 20030509
    source: RIPE

    role: Mannesmann Arcor Network Operation Center
    address: Arcor AG & Co.KG
    address: Department TBN
    address: Otto-Volger-Str. 19
    address: D-65843 Sulzbach/Ts.
    address: Germany
    phone: +49 6196 523 0864
    e-mail: noc@adm.arcor.net
    trouble: Security issues mailto:abuse@arcor-ip.de
    trouble: Information http://www.arcor.net
    trouble: Peering contact mailtoeering@adm.arcor.net
    trouble: Operational issues mailto:noc@adm.arcor.net
    trouble: Address assignment mailto:ip-registry@arcor.net
    admin-c: PN667-RIPE
    admin-c: SM9000-RIPE
    admin-c: JS19072-RIPE
    admin-c: DH6636-RIPE
    admin-c: AR9338-RIPE
    admin-c: TK11590-RIPE
    admin-c: RH12597-RIPE
    admin-c: MW877-RIPE
    tech-c: NH15-RIPE
    nic-hdl: ANOC1-RIPE
    notify: ip-registry@arcor.net
    mnt-by: ARCOR-MNT
    changed: ip-registry@arcor.net 20011213
    changed: ip-registry@arcor.net 20020926
    changed: ip-registry@arcor.net 20030620
    changed: ip-registry@arcor.net 20031223
    changed: ip-registry@arcor.net 20040504
    source: RIPE
    Chief Lemon Buyer no more Linux sucks but not as much
    Weather nut and sad git.

    My Weather Page

  • #2
    That looks awfully like someone installing a backdoor onto your system.

    212.23.37.32:http Fin_Wait_1
    The line above tells me that a connection is open from that address. "Fin" is a reference to "finish" for a tcp connection. Hmm, let me open my tcp book, will post more in a minute.
    Ladies and gentlemen, take my advice, pull down your pants and slide on the ice.

    Comment


    • #3
      OK, so fin_wait_1 state means that an application finished what it was doing and requested the session to be closed. But it seems the application is from your side and that we are waiting for the other side to acknowledge that we want to close the session. This is part of the handshake for any TCP session when it wants to close. We are wiating for an acknowledgement from teh other side and not getting it.

      Hope this helps.

      Dave
      Ladies and gentlemen, take my advice, pull down your pants and slide on the ice.

      Comment


      • #4
        Do a search on your hard drives for .zip, .rar, whatever. See if you've become a repository.

        Also, do you have outbound SMTP blocked? Maybe you're spamming.
        Gigabyte P35-DS3L with a Q6600, 2GB Kingston HyperX (after *3* bad pairs of Crucial Ballistix 1066), Galaxy 8800GT 512MB, SB X-Fi, some drives, and a Dell 2005fpw. Running WinXP.

        Comment


        • #5
          Nothing strange under compressed files.
          Spyboy, Adaware and 30 day trail version of pest control corperation version found zippo. Nortons anti viri is running now.

          Machine is a two week clean install of XP sp2 and is patched up todate. The install was done with the network disconnected.

          The machine does run vpn to the University I work for and theres tons of shit on that network.

          Hijack this shows nothing that shouldn't be there.

          Mmmmm.

          Oh which port does smtp broadcast on?
          Chief Lemon Buyer no more Linux sucks but not as much
          Weather nut and sad git.

          My Weather Page

          Comment


          • #6
            Even more interesting if I type in the IP address in the url it asks me to login.
            Chief Lemon Buyer no more Linux sucks but not as much
            Weather nut and sad git.

            My Weather Page

            Comment


            • #7
              netstat -o will tell you which / what process ID initiatated the connection so that you might be able to track it down better.

              Also XP SP2 firewall is able to log successful connections, might want to enable it and on ur next reboot check its logs to see if it shows any other funny business.
              Go Bunny GO!


              Titan:
              MSI NEO2-FISR | Intel P4-3.0C | 1024MB Corsair TWINX1024 3200LLPT RAM | ATI AIW 9700 Pro | Dell P780 @ 1024x768x32 | Turtle Beach Santa Cruz | Sony DRU-500A DVD-R/-RW/+R/+RW | WDC 100GB [C:] | WDC 100GB [D:] | Logitech MX-700

              Mini:
              Shuttle SB51G XPC | Intel P4 2.4Ghz | Matrox G400MAX | 512 MB Crucial DDR333 RAM | CD-RW/DVD-ROM | Seagate 80GB [C:] | Logitech Cordless Elite Duo

              Server:
              Abit BE6-II | Intel PIII 450Mhz | Matrox Millennium II PCI | 256 MB Crucial PC133 RAM | WDC 6GB [C:] | WDC 200GB [E:] | WDC 160GB [F:] | WDC 250GB [G:]

              Comment


              • #8
                Well at the moment it's gone. The only things running are connections to the university.
                Chief Lemon Buyer no more Linux sucks but not as much
                Weather nut and sad git.

                My Weather Page

                Comment


                • #9
                  http://www.sysinternals.com/ is your friend, tcpview and process explorer.

                  Comment


                  • #10
                    Can you get this too log events during bootup????
                    Chief Lemon Buyer no more Linux sucks but not as much
                    Weather nut and sad git.

                    My Weather Page

                    Comment


                    • #11
                      I don't know if they will. They are great tools to monitor network activity if you think something fishy is going on. You can try and see if the XP SP2 firewall log file will log connections attempted/made during bootup/startup. Good luck!
                      Go Bunny GO!


                      Titan:
                      MSI NEO2-FISR | Intel P4-3.0C | 1024MB Corsair TWINX1024 3200LLPT RAM | ATI AIW 9700 Pro | Dell P780 @ 1024x768x32 | Turtle Beach Santa Cruz | Sony DRU-500A DVD-R/-RW/+R/+RW | WDC 100GB [C:] | WDC 100GB [D:] | Logitech MX-700

                      Mini:
                      Shuttle SB51G XPC | Intel P4 2.4Ghz | Matrox G400MAX | 512 MB Crucial DDR333 RAM | CD-RW/DVD-ROM | Seagate 80GB [C:] | Logitech Cordless Elite Duo

                      Server:
                      Abit BE6-II | Intel PIII 450Mhz | Matrox Millennium II PCI | 256 MB Crucial PC133 RAM | WDC 6GB [C:] | WDC 200GB [E:] | WDC 160GB [F:] | WDC 250GB [G:]

                      Comment


                      • #12
                        This won't help if you want to log during boot (at least I don't think so, I've never tried or had a reason to try) but Ethereal is a nice open-source packet analyzer, great for when you want to know what exactly is going over your connection.

                        Comment

                        Working...
                        X