Re: AltaVista_Traversal attack from mod-pubsub.org?

"Asynch Messaging" <[email protected]> Thu, 9 Oct 2003 20:30:41 -0700
Newsgroups gmane.comp.web.mod-pubsub.devel
Message-ID <[email protected]>
Also, the attacked ports seem to be within the range of 'ephemeral' port
numbers.
I was pretty skeptical that this was an attack, but now I'm convinced it's
some misinterpretation.

Move along. These are not the droids you're looking for.

----- Original Message ----- 
From: "Ben Sittler" <[email protected]>
To: "S. Mike Dierken" <>; "Adam Rifkin" <[email protected]>
Cc: <[email protected]>
Sent: Wednesday, October 08, 2003 9:41 AM
Subject: RE: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?


Hi Mike,

That's good information -- it tells us that the remote port is 9000, which
is used only for *inbound* socket connections to mod-pubsub.org's python
server. This looks to me like a firewall mis-interpreting our pushed HTTP
response as an attack!

So, how does one go about contacting the firewall maker to get them to
recognize our HTTP usage as non-threatening?

-Ben

-----Original Message-----
From: S. Mike Dierken [mailto:]
Sent: Tue 10/7/2003 8:44 PM
To: Ben Sittler; Adam Rifkin
Cc: [email protected]
Subject: Re: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?
I also thought it strange that my firewall would report incoming requests
from mod-pubsub.org.
It could very well be some weird Symantec firewall mis-reporting of outbound
traffic.
The 'attacked port' is different each time.

10/05/2003 10:15:04PM
      Details: Attempted Intrusion "AltaVista_Traversal" against your
machine was detected and blocked
      Intruder: 64.161.22.235(9000)
      Risk Level: High
      Protocol: TCP
      Attacked IP: nautilus(207.202.171.254).
      Attacked Port: 2800

      Click on the address to trace the attacker
      You can get detailed information about this attack at Symantec
Security Response


10/05/2003 10:02:53PM
      Details: Attempted Intrusion "AltaVista_Traversal" against your
machine was detected and blocked
      Intruder: 64.161.22.235(9000)
      Risk Level: High
      Protocol: TCP
      Attacked IP: nautilus(207.202.171.254).
      Attacked Port: 2753

      Click on the address to trace the attacker
      You can get detailed information about this attack at Symantec
Security Response


(also one from 2003-10-03T21:02:17 and some on 2003-10-04)

----- Original Message ----- 
From: "Ben Sittler" <[email protected]>
To: "S. Mike Dierken" <>; "Adam Rifkin" <[email protected]>
Cc: <[email protected]>
Sent: Monday, October 06, 2003 2:18 PM
Subject: RE: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?


Hi Mike,

I may misunderstand, but I believe the "spurious" request is not actually
coming back to the client IP -- rather the firewall is detecting this in the
*outgoing* direction, as part of a hidden form submission (or other client
library request.) If you have reason to believe mod-pubsub.org is opening
sockets into your client machine, do let us know the details!

The python pubsub server (at the moment the only pubsub server really in use
at mod-pubsub.org) *should be* incapable of opening an outbound socket
connection -- it relies entirely on client-initiated sockets for all
communication.

Looking forward to more details...

-Ben

-----Original Message-----
From: S. Mike Dierken [mailto:]
Sent: Sun 10/5/2003 5:58 PM
To: Ben Sittler; Adam Rifkin
Cc: [email protected]
Subject: Re: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?
I don't know if ".." is supported in URI, but form data should be okay.
Either one is fine by me, I'm just curious why a request would come back to
the client IP address?

----- Original Message ----- 
From: "Ben Sittler" <[email protected]>
To: "S. Mike Dierken" <>; "Adam Rifkin" <[email protected]>
Cc: <[email protected]>
Sent: Sunday, October 05, 2003 4:43 PM
Subject: RE: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?


Apparently this means we sometimes submit form data with "../" in it. I
regard this as correct behavior (we don't use that to circumvent security,)
and see no reason to change our data format to work around this particularly
harmful firewall heuristic. Your thoughts?

-Ben

-----Original Message-----
From: [email protected] on behalf of S. Mike
Dierken
Sent: Sat 10/4/2003 9:20 PM
To: Adam Rifkin
Cc: [email protected]
Subject: [Mod-pubsub-developer] AltaVista_Traversal attack from
mod-pubsub.org?
I'm seeing Norton Internet Firewall detect an attack sourced at
mod-pubsub.org whenever I connect to the chat server there. It claims an
attack similar to the AltaVista_Traversal is ocurring. Different incoming
ports are reported.

Does anybody know what this means?



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Mod-pubsub-developer mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-pubsub-developer











-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php