Not Registered? Sign Up Now!
myNetWatchman Privacy Statement

Log in for advanced features

E-mail:

Password:

 
  Remember Me

mNW Reports  FAQ: mNW Reports






(Registered Users Only)


Look Up Incidents by IP Address

 

 

Latest News

2006-08-15Mocbot observed propagating via tcp/445 and MS06-040 exploit.

2005-01-05 — Successfully moved myNetWatchman servers to our new hosting facility. The move gives us better bandwidth and space.

2004-07-01New FAQ answers added to help new users get started. Many thanks to mNW user Jack Eisenberg for compiling this info.

2004-06-01New mNW Agent to support Kerio Winroute Firewall 5.x and 6.x.. A new mNW agent has been developed to convert Kerio 's log into ZoneAlarm's format. Instructions are included with the downloaded file. Many thanks to Jiggs for developing this tool.

2004-04-01Improved myNetWatchman Notification Routing Policy. Effective March 1, 2004 we changed our approach to identifying and notifying the responsible party associated with myNetWatchman (mNW) detected security incidents. Previously, we used a combination of reverse DNS, DNS Start-of-Authority, and IP Whois information to identify the responsible party. However, have concluded that this approach is unscalable and ineffective for all but the largest network providers.

2004-03-22Messenger Spammers Now Fragging. Changes in UDP/1026 and UDP/1027 activity (usually attributable to Windows Messenger Spam) show that message size is increasing beyond the typical maximum packet size. A side effect of that is a substantial increase in 'fragment reassembly timeout' errors. Since a significant percentage of Messenger spam is transmitted using a forged source IP, the unfortunate owners of these IPs will likely notice a significant volume of inbound ICMP error packets which can significantly degrade performance.

More News

  

The Windows Messenger service enabled can leave your system open to anyone on the Internet. Make sure your system isn't vulnerable with this one-click test.
 

myNetWatchman wants your help to secure the internet. Consider participating in our Adopt-a-Neighbor and Adopt-a-State programs.
 
  FAQ: mNW Stats
Active Agents305
Countries/States34 / 34
Resolved Attacks28

Today's Events:
- Firewall events1,684,659
- New Attackers1,022
- Re-escalations0
- Total attackers1,022
- Resolved attacks5
Last Hour's Events 
 
Ports Rising in Attack Rates [Full Report]FAQ: mNW Reports
Protocol/
Port
Registered Use/
Unregistered Use
Day's
Share
Increase
tcp/1433  
mNW Incidents
mNW Info
Microsoft SQL
Spida Worm
10.9%4.2%
tcp/139  
mNW Incidents
mNW Info
NETBIOS Session Service
NETBIOS Session Service
17.2%1.7%
udp/135  
mNW Incidents
mNW Info
epmap
Possible Messenger SPAM attemp
1.7%1.5%
tcp/5900  
mNW Incidents
mNW Info

VNC crack attempt?
2.0%1.2%
tcp/1080  
mNW Incidents
mNW Info
SOCKS Proxy
SOCKS Proxy
1.4%0.7%
  
Ports Being Attacked Most [Full Report]FAQ: mNW Reports
Protocol/
Port
Registered Use/
Unregistered Use
Day's
Share
tcp/445  
mNW Incidents
mNW Info
Microsoft SMB/CIFS
Sasser/Agobot/GenericBot
28.1%
udp/1434  
mNW Incidents
mNW Info
ms-sql-m
SQL Slammer Worm
20.3%
tcp/139  
mNW Incidents
mNW Info
NETBIOS Session Service
NETBIOS Session Service
17.2%
tcp/1433  
mNW Incidents
mNW Info
Microsoft SQL
Spida Worm
10.9%
tcp/135  
mNW Incidents
mNW Info
DCE endpoint resolution
Msblast/Nachi?
6.5%
 
Most Recently Resolved Incidents [Full Report]FAQ: mNW Reports
Time Closed (UTC)ISPIncident IDComment
8 Jul 2008 19:49:23techvalleycom.com696132Responsible party indicated that the customer was warned.
8 Jul 2008 16:46:28netdirekt.de868273Infection via 71.33.236.177 (notified).
8 Jul 2008 14:34:10colosseum.com413419We are working with our client to resolve their compromised server. Our apologies to those who have experienced brute-force SSH hack attempts, and our thanks for your reports!
8 Jul 2008 12:32:44renater.fr874772Responsible party indicated that the customer was warned.
8 Jul 2008 09:53:06hp.com267332Upon investigation, CITSIRT has been unable to locate the machine referenced. The IP address 15.235.147.254 is in the netblock assigned to HP, but no machine with that IP address was located. In fact, there is no such active subnet within HP. Thus, it is likely that the IP address was spoofed. Regards, Hanns Balzer HP IT Security CITSIRT: Corporate IT Security Incident Response Team Hotline: +1-650-857-5120 / citsirt@hp.com / http://citsirt.itsecurity.hp.com