Should these ports be used by WBS?

doublefrangelico

Active Member
Joined
Oct 25, 2005
Messages
53
Reaction score
0
I noticed that many of the incoming attempts to access my Internet-connected PC were on port 135 and 445. The attempts were from WBS addresses.

I also noticed that it happened every time that a host name was resolved to an IP.

These are RPC locator service and netbios ports, not so?

This is not normal is it?
 
Last edited:
doublefrangelico said:
I noticed that many of the incoming attempts to access my Internet-connected PC were on port 135 and 445. The attempts were from WBS addresses.

I also noticed that it happened every time that a host name was resolved to an IP.

These are RPC locator service and netbios ports, not so?

This is not normal is it?

Those are fle and print sharing/netbios sessions.Which WBS addresses ? if it'
s something like wbs-196-??-??-???.wbs.co.za then it would be a fellow iBurster or iBurster's PC just broadcasting 'looking for friends' or someone trying to get to your PC or just network traffic.Some malicious malware may also use these ports......so....if you not expecting anyone at your PC's doorstep...block it if you want. unless you want to share on a LAN.
 
I concur with the first post here, every day I get hundreds of inbound events from WBS IPs.

I use a firewall which blocks access to the ports from outside. But these are my hits from yesterday

196.46.67.95
196.463.66.121
196.463.66.83
196.46.70.196
196.46.70.144

to ports
135
139
445

I had approx 50 recorded inbound events from these addresses for yesterday.

Do these addresses belong to Iburst (and its servers) themselves? Does a tower have its own IP? It might explain some of this perhaps. Or is it something more sinister? Or am I being paranoid and believe that everyone on the net is out to get me? :)

Andy



But If anyone knows I'd really like an explanation for all this.
 
Those IP's,..are DHCP assigned IP's to the clients of CT in the iBurst network. So therefore, if you are getting "attacks" from those IP's, then it’s the user of those machines.

They are either doing it willingly, or have some sort of virus that is doing it for them....
 
But could so many users realy have a virus that can target other Iburst PC's?
Im not really shure how this would work, I dont think a virus could see another Iburst PC from its infected one.

Iburst PC arent really connected to one another as in sharing being possible between them are they? And I doubt there are 50 Ibursters just cruising the iburst IP range everyday.

I also get these "attacks" though, but they really stump me. Maby someone should phone WBS about it and get told to change their MTU? Could solve all our problems..
 
Last edited:
Now for the 9 million dollar question....

Does this inbound traffic count towards my cap? At the very least it is interfering with my bandwidth, however negligible that may seem.

Another point...
My firewall hides me from being detected on the Internet. According to Zonealarm I am virtually invisible. Of course when I connect to a site, they know I'm there.
But these spurious incoming attempts are initiated after a DNS lookup. Does this mean that WBS is putting my PC at risk? I don't get these attempts from anywhere else but these wbs-196-??-??-???.wbs.co.za hosts and only after a DNS lookup. Thus by doing a DNS lookup to WBS's servers, WBS is allowing the multitude of virus-laden IBurst-subscribers to "see" my PC and as a result, attempt to access my PC....

I'm not sure if this is possible, but That's been my observations...

Any comments?
 
Last edited:
I've spoken to Iburst and they've promised to investigate the issues reported here. I've referenced this forum topic in my conversation and email that I've sent as further evidence of the reported incident

Let see what they say.

Andy

(I have far too much time on my hands)
 
Wow.. that doesnt sound too bad for a respone from them. You shure they didnt tell you to change your MTU?

Now we can see how good the new support team or whatever really is.
 
Ekhaatvensters said:
Wow.. that doesnt sound too bad for a respone from them. You shure they didnt tell you to change your MTU?

Now we can see how good the new support team or whatever really is.

Stop using that MTU setting comment, makes me giggle like a girl you sadistic bugger :D
 
this has always seemed to be a problem on iburst. they definetly need to educate some users on spyware and malware. maybe bundle a firewall in their setup.

I am using kerio personal firewall which is pretty uber... funny though i dont get as many attacks i used to with zone alarm or mcaffee.

as for bandwidth these attacks take... its something like 5mb for the whole month. not even.
 
Well that sounds about fine.. well, gigling like a little girl and using up 5mb that is.

I also noticed alot more "attacks" using ZA, but I think its becuase I actually checked the logs, it is a startlig amount though.. what do you think these entry attemps would do if they weree let thoruhg.. i.e no firewall like most iburst users probably have.
 
My train of thought is this:
Firewall is quiet
Firewall is quiet
Firewall is quiet
As soon as my PC tries to resolve a host name at the DNS server, I get these attempts to access my PC from 4 or 5 WBS subscriber IP's.

Now think about this....
1) Why only when I access the DNS server?
2) Is someone Scanning my packets? this shouldn't be possible if there are routers on the network? true or false?
3) If I assume that noone is scanning my packets, then the next explanation is that the DNS server is the only one that knows I am active based on the recent request. (I had my firewall temporarily set to not allow responses from the DNS through, thus I was not accessing the requested internet hosts and thus I knew that the attempts were as a result of accessing the DNS server)
So.....if the DNS server is the only one that knows that I am active, and I am being probed as a result of the DNS lookup, then what is the logical conclusion..?
DNS server compromised?

Am I being paranoid here?
 
doublefrangelico said:
Am I being paranoid here?

No.

I get 30-50 incoming attacks per hour from wbs addresses on port 135/445... but only when my account is active. When my account is quiet, the attacks stop.

Your theory appears quite sound to me.

Unless someone else has a more plausible theory...
 
But you guys must see that this cant really be much a serious threat. It has been happening since Iburts started, or atleast since I got it, and its not like we are all very prone to viruses around here right?

I used to get alot more viruses with dialup infact, probably just my security habits though.

But it cant really be very dangerous, tons of poepl run Iburst withour firewalls, or maby just XP firewall on and im shure they arent all reieving viruses through about 50 attacks a day. Maby it is simply something to do with the way Iburst works, those adresses could be special ones at the basestation or something, like you say its only when you look up an IP.
If it was an "planned" attack it couldnt only happen at one specific time.

Oh, not like this is plausable theory, im just thinking it cant really be a very serious "compromsing" of the DNS server, as nothing sems to go wrong.
 
I think these 'attacks' are actually related to attempts to esablish a VPN connection. I use IPCOP between my client and myself both of us with iburst. Once an Iburst connection is made, IPCOP updates its wbs ip address at dyndns.org. The other unit then attempts to connect to this address. If the connection is lost, then ipcop attempts to re-establish this connection, not knowing that IP address is now in use by another IBURST unit. I did confirm that port 445 does get used by VPN.
 
patrick123 said:
I think these 'attacks' are actually related to attempts to esablish a VPN connection. I use IPCOP between my client and myself both of us with iburst. Once an Iburst connection is made, IPCOP updates its wbs ip address at dyndns.org. The other unit then attempts to connect to this address. If the connection is lost, then ipcop attempts to re-establish this connection, not knowing that IP address is now in use by another IBURST unit. I did confirm that port 445 does get used by VPN.

Patrick123, i really doubt that so many ppl are using iburst to VPN. Some do, but that is really quite a minority...
 
You'd be surprised how many ppl really do use VPN. And stop follwing me through threads :)
 
You don't need many people. All you need is your unit to receive an IP address that another unit had published at dyndns.org. Thereafter the 'Roadwarrior' or another 'net-to-net' VPN will attempt numerous times to re-establish the connection they had with their host network.
 
Top
Sign up to the MyBroadband newsletter
X