Network invasion?
Results 1 to 9 of 9

Thread: Network invasion?

  1. #1
    Registered User
    Join Date
    Nov 2000
    Location
    Houston,TX,usa
    Posts
    20

    Network invasion?

    I received the following message form my ISP, (ATT_, I am on a T-1 there is no server just a router and a few switches and about 75 desktops. Right before I received this message I could notice a considerable slowdown in my Internet speed, which still continues. Have been going from desktop to desktop to try and figure where the problem is without any luck. Any ideas would be great; I know desktops but come up a little short on networks. The x's is my gateway

    A host (xx.xx.xx.xx) within your IP block may be
    Infected with a Trojan, virus, or worm; or you may have a
    Malicious user on your network. The host in question,
    ((xx.xx.xx.xx) ), is sending unsolicited commercial email (spam).
    (xx.xx.xx.xx) is your firewall/gateway/NAT then it is
    likely that the offending email is originating from your
    Internal network.

  2. #2
    Registered User CeeBee's Avatar
    Join Date
    Nov 2002
    Location
    USA
    Posts
    2,494
    so investigate your clients - set some monitoring and see who's generating the traffic...

  3. #3
    Registered User
    Join Date
    Nov 2000
    Location
    Houston,TX,usa
    Posts
    20
    On Question how do I do that. Like I said I know desktops not networks. All running XP Pro. Static Ip's using netgear router.

  4. #4
    Registered User CeeBee's Avatar
    Join Date
    Nov 2002
    Location
    USA
    Posts
    2,494
    Try to use a tool like Cain to capture traffic and see who is trying to reach port 25. Or if the router allows, block port 25 and have the router log the attempt. Or run a netstat script on all machines and see who is connecting to port 25 on other hosts.
    Edit: some antivirus packages treat Cain as a "malicious" program, you may have to remove the install folder from the scanning.

  5. #5
    Registered User
    Join Date
    Nov 2000
    Location
    Houston,TX,usa
    Posts
    20

    Cain?

    Only Cain program I can find is for password recovery

  6. #6
    Registered User xpuser357's Avatar
    Join Date
    Apr 2004
    Location
    Poplar Bluff, Mo.
    Posts
    1,328
    http://sectools.org/sniffers.html Maybe this might help.

  7. #7
    Registered User
    Join Date
    Nov 2000
    Location
    Houston,TX,usa
    Posts
    20
    Now I'm feeling like a complete fool. Have downloaded and installed Cain but have no idea how to use it. Have tried the help files to no avail. How do I capture traffic? System is still bogging down and I'm lost.

  8. #8
    Registered User Smokin Joe's Avatar
    Join Date
    May 2005
    Posts
    90

    Spyware?

    smghou
    I recieved a message just like yours

    A host (xx.xx.xx.xx) within your IP block may be
    Infected with a Trojan, virus, or worm; or you may have a
    Malicious user on your network. The host in question,
    ((xx.xx.xx.xx) ), is sending unsolicited commercial email (spam).
    (xx.xx.xx.xx) is your firewall/gateway/NAT then it is
    likely that the offending email is originating from your
    Internal network.

    After discovering that spyware can stop internet access I won't let anyone access my network without continuously running a version of spydoctor as well as Norton antivirus. The earlier version of spydoctor 3 something works just fine and doesn't grind the computer into the ground.

    My next step was to check every computer and see if either had been disabled.
    When I found the computer and reactivated the spydoctor, did a cleansing the network returned to normal.
    The operator was given a warning (final)
    Hope this helps

  9. #9
    Registered User CeeBee's Avatar
    Join Date
    Nov 2002
    Location
    USA
    Posts
    2,494
    Quote Originally Posted by smghou
    Only Cain program I can find is for password recovery
    The sniffer in Cain can sniff for well-known services, including SMTP

Similar Threads

  1. [RESOLVED] 70-240: LETS DO THIS!!
    By 70-240 in forum Certification
    Replies: 14
    Last Post: February 20th, 2012, 03:35 AM
  2. Media Center Edition 2005 & Mapped Network Drive
    By pbolduc in forum Networking
    Replies: 0
    Last Post: April 25th, 2007, 01:24 PM
  3. Peer to peer home network permissions
    By MorseLady in forum Networking
    Replies: 9
    Last Post: April 27th, 2005, 12:31 PM
  4. Is this too good to be true?
    By gizmo1_1 in forum Tech-To-Tech
    Replies: 28
    Last Post: October 16th, 2004, 10:20 PM
  5. Internet Connection Sharing
    By Jared Job in forum Windows 95/98/98SE/ME
    Replies: 20
    Last Post: October 2nd, 2000, 05:39 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •