Not Registered? Sign Up Now!
myNetWatchman Privacy Statement

Log in for advanced features

E-mail:

Password:

 
  Remember Me

mNW Reports  FAQ: mNW Reports






(Registered Users Only)


Look Up Incidents by IP Address

 

 

Latest News

2006-08-15Mocbot observed propagating via tcp/445 and MS06-040 exploit.

2005-01-05 — Successfully moved myNetWatchman servers to our new hosting facility. The move gives us better bandwidth and space.

2004-07-01New FAQ answers added to help new users get started. Many thanks to mNW user Jack Eisenberg for compiling this info.

2004-06-01New mNW Agent to support Kerio Winroute Firewall 5.x and 6.x.. A new mNW agent has been developed to convert Kerio 's log into ZoneAlarm's format. Instructions are included with the downloaded file. Many thanks to Jiggs for developing this tool.

2004-04-01Improved myNetWatchman Notification Routing Policy. Effective March 1, 2004 we changed our approach to identifying and notifying the responsible party associated with myNetWatchman (mNW) detected security incidents. Previously, we used a combination of reverse DNS, DNS Start-of-Authority, and IP Whois information to identify the responsible party. However, have concluded that this approach is unscalable and ineffective for all but the largest network providers.

2004-03-22Messenger Spammers Now Fragging. Changes in UDP/1026 and UDP/1027 activity (usually attributable to Windows Messenger Spam) show that message size is increasing beyond the typical maximum packet size. A side effect of that is a substantial increase in 'fragment reassembly timeout' errors. Since a significant percentage of Messenger spam is transmitted using a forged source IP, the unfortunate owners of these IPs will likely notice a significant volume of inbound ICMP error packets which can significantly degrade performance.

More News

  

The Windows Messenger service enabled can leave your system open to anyone on the Internet. Make sure your system isn't vulnerable with this one-click test.
 

myNetWatchman wants your help to secure the internet. Consider participating in our Adopt-a-Neighbor and Adopt-a-State programs.
 
  FAQ: mNW Stats
Active Agents336
Countries/States32 / 33
Resolved Attacks497

Today's Events:
- Firewall events1,516,576
- New Attackers875
- Re-escalations278
- Total attackers1,153
- Resolved attacks6
Last Hour's Events 
 
Ports Rising in Attack Rates [Full Report]FAQ: mNW Reports
Protocol/
Port
Registered Use/
Unregistered Use
Day's
Share
Increase
tcp/1433  
mNW Incidents
mNW Info
Microsoft SQL
Spida Worm
10.9%4.2%
tcp/139  
mNW Incidents
mNW Info
NETBIOS Session Service
NETBIOS Session Service
17.2%1.7%
udp/135  
mNW Incidents
mNW Info
epmap
Possible Messenger SPAM attemp
1.7%1.5%
tcp/5900  
mNW Incidents
mNW Info

VNC crack attempt?
2.0%1.2%
tcp/1080  
mNW Incidents
mNW Info
SOCKS Proxy
SOCKS Proxy
1.4%0.7%
  
Ports Being Attacked Most [Full Report]FAQ: mNW Reports
Protocol/
Port
Registered Use/
Unregistered Use
Day's
Share
tcp/445  
mNW Incidents
mNW Info
Microsoft SMB/CIFS
Sasser/Agobot/GenericBot
28.1%
udp/1434  
mNW Incidents
mNW Info
ms-sql-m
SQL Slammer Worm
20.3%
tcp/139  
mNW Incidents
mNW Info
NETBIOS Session Service
NETBIOS Session Service
17.2%
tcp/1433  
mNW Incidents
mNW Info
Microsoft SQL
Spida Worm
10.9%
tcp/135  
mNW Incidents
mNW Info
DCE endpoint resolution
Msblast/Nachi?
6.5%
 
Most Recently Resolved Incidents [Full Report]FAQ: mNW Reports
Time Closed (UTC)ISPIncident IDComment
11 May 2008 09:22:56staminus.net293255941Comprimised PsyBNC. User account password changed, and new PsyBNC installed. Firewall ruleset modified to detect should it repeat itself.
11 May 2008 07:07:09iif.hu293040930Responsible party indicated that the customer was warned.
11 May 2008 06:46:56iif.hu293825035Responsible party indicated that source host was compromised and has been cleaned or taken offline.
11 May 2008 06:45:26iif.hu293547349Forwarded to operators of Heves Megyei Leveltar network
11 May 2008 06:44:25iif.hu294082250Forwarded to operators of Heves Megyei Leveltar network