Re: Website link for 208.24.247.131
"Alexey Lobanov (dsbl)" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Organization | DSBL volunteer |
| Message-ID | <[email protected]> |
Hello.
On 18/02/06 22:02, Peter Knowles wrote:
> Alexey:
>
> Thank you for your response.
>
> After some additional investigation, I've learned that the server was indeed
> infected with some viruses/malware last month. From what I am told, the
> system has been 'cleaned up'. I am auditing the system this weekend.
>
> As far as UNIX is concerned, I do not have the resources (time, money, brain
> power, other staff, etc.) to put up another OS, hence relying on your
> generosity; I appreciate your help by testing the server.
The port scan is over; fortunately, nothing suspicious was found. The
only possible problem may be too liberal firewall setting. Are you sure
that whole Internet should be able to test the strength of MS remote
desktop passwords at this machine? In practice, real remote users
normally work from quite limited set of networks.
===
Starting nmap 3.81 ( http://www.insecure.org/nmap/ ) at 2006-02-18 21:37 MSK
Initiating SYN Stealth Scan against
upstatemail.upstate.1199union.1199.org (208.24.247.131) [65535 ports] at
21:37
The SYN Stealth Scan took 1631.39s to scan 65535 total ports.
Interesting ports on upstatemail.upstate.1199union.1199.org
(208.24.247.131):
(The 65507 ports scanned but not shown below are in state: filtered)
PORT STATE SERVICE
25/tcp open smtp
80/tcp open http
3389/tcp open ms-term-serv
Nmap finished: 1 IP address (1 host up) scanned in 1641.563 seconds
Raw packets sent: 131342 (5.25MB) | Rcvd: 341 (15.8KB)
==============
So, I advice you to find the message to <[email protected]> dated
2006/Feb/15 21:06:32 UTC and confirm it as soon as possible.
best,
Alexey
>
> -----Original Message-----
> From: Alexey Lobanov (dsbl) [mailto:[email protected]]
> Sent: Saturday, February 18, 2006 1:50 PM
> To: Peter Knowles
> Cc: '[email protected]'
> Subject: Re: [DSBL-Contact] Website link for 208.24.247.131
>
> Hi Peter.
>
> On 18/02/06 00:17, Peter Knowles wrote:
>
>> I am an outside consultant for the organization using the above IP for
>> email. I do not have access to the admin mailboxes.
>>
>> My reason for contacting you is to see whether you can verify whether this
>> server still exhibits the vulnerabilities noted within the listing
>
> This specific port 10995 does not reply... and it means nothing.
> Uncommon high port numbers are more typical for malware then for
> legitimate servers. And malware proxies like to change port numbers in
> random way, so it is very normal that this 10995 does not reply now. Was
> it malware or a legitimate server? This question must be addressed to
> *you*, sir.
>
>> (HTTP-CONNECT, HTTP-PUT). I am told there was some remedial work done on
> the
>> server since the listing.
>>
>> We do not have access to UNIX/LINUX hardware to run any of the testing
>> modules offered on your website.
>
> To my knowledge, all modern Unix flavours (even MacOS since last week
> ;-) are able to run in plain consumer-grade PC hardware. I am not sure
> that I understand your difficulties.
>
>> Once I can verify that the server is secure, I will escalate the
> responsible
>> person in the organization to proceed with the proper de-listing
> procedures.
>> Thank you for any assistance and input you can provide.
>
> Anyway, according to your request I am running a portscanner (nmap)
> against 208.24.247.131 now. The result will be reported, but it may take
> from one to dozens hours, depending upon your firewall settings.
>
> Alexey
> DSBL volunteer
>
>
>> Peter Knowles
>>