Re: Website link for 208.24.247.131

"Alexey Lobanov (dsbl)" <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Organization DSBL volunteer
Message-ID <[email protected]>
Hello.

On 18/02/06 22:02, Peter Knowles wrote:

> Alexey:
> 
> Thank you for your response.
> 
> After some additional investigation, I've learned that the server was indeed
> infected with some viruses/malware last month. From what I am told, the
> system has been 'cleaned up'. I am auditing the system this weekend.
> 
> As far as UNIX is concerned, I do not have the resources (time, money, brain
> power, other staff, etc.) to put up another OS, hence relying on your
> generosity; I appreciate your help by testing the server.

The port scan is over; fortunately, nothing suspicious was found. The 
only possible problem may be too liberal firewall setting. Are you sure 
that whole Internet should be able to test the strength of MS remote 
desktop passwords at this machine? In practice, real remote users 
normally work from quite limited set of networks.

===

Starting nmap 3.81 ( http://www.insecure.org/nmap/ ) at 2006-02-18 21:37 MSK
Initiating SYN Stealth Scan against 
upstatemail.upstate.1199union.1199.org (208.24.247.131) [65535 ports] at 
21:37

The SYN Stealth Scan took 1631.39s to scan 65535 total ports.

Interesting ports on upstatemail.upstate.1199union.1199.org 
(208.24.247.131):
(The 65507 ports scanned but not shown below are in state: filtered)
PORT     STATE  SERVICE
25/tcp   open   smtp
80/tcp   open   http
3389/tcp open   ms-term-serv

Nmap finished: 1 IP address (1 host up) scanned in 1641.563 seconds
                Raw packets sent: 131342 (5.25MB) | Rcvd: 341 (15.8KB)

==============

So, I advice you to find the message to <[email protected]> dated 
2006/Feb/15 21:06:32 UTC  and confirm it as soon as possible.

best,
Alexey


> 
> -----Original Message-----
> From: Alexey Lobanov (dsbl) [mailto:[email protected]]
> Sent: Saturday, February 18, 2006 1:50 PM
> To: Peter Knowles
> Cc: '[email protected]'
> Subject: Re: [DSBL-Contact] Website link for 208.24.247.131
> 
> Hi Peter.
> 
> On 18/02/06 00:17, Peter Knowles wrote:
> 
>> I am an outside consultant for the organization using the above IP for
>> email. I do not have access to the admin mailboxes.
>>
>> My reason for contacting you is to see whether you can verify whether this
>> server still exhibits the vulnerabilities noted within the listing
> 
> This specific port 10995 does not reply... and it means nothing.
> Uncommon high port numbers are more typical for malware then for
> legitimate servers. And malware proxies like to change port numbers in
> random way, so it is very normal that this 10995 does not reply now. Was
> it malware or a legitimate server? This question must be addressed to
> *you*, sir.
> 
>> (HTTP-CONNECT, HTTP-PUT). I am told there was some remedial work done on
> the
>> server since the listing.
>>
>> We do not have access to UNIX/LINUX hardware to run any of the testing
>> modules offered on your website.
> 
> To my knowledge, all modern Unix flavours (even MacOS since last week
> ;-) are able to run in plain consumer-grade PC hardware. I am not sure
> that I understand your difficulties.
> 
>> Once I can verify that the server is secure, I will escalate the
> responsible
>> person in the organization to proceed with the proper de-listing
> procedures.
>> Thank you for any assistance and input you can provide.
> 
> Anyway, according to your request I am running a portscanner (nmap)
> against 208.24.247.131 now. The result will be reported, but it may take
> from one to dozens hours, depending upon your firewall settings.
> 
> Alexey
> DSBL volunteer
> 
> 
>> Peter Knowles
>>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.