LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-06-2009, 04:51 AM   #1
oodlebonse
LQ Newbie
 
Registered: Mar 2007
Posts: 4

Rep: Reputation: 0
Cool why am i getting loads of hits off m$ ip's?


i use iplist as a blocker, and over the last few weeks i have noticed a sudden increase in the ammount of m$ ip's being refused. these are incoming connections, and i cant seem to fathom it out, as i have reason to connect to micro$oft, except for using the msn protocol, but i cant see where this could cause all the refused connections i keep seeing. i am not quite a noob, but neither am i a linux whizz (i wish).

if anyone could come up with some sort of explaination for this, or even a solution for stopping this, i would be extremely gratefull.

i use ubuntu 8.04, i'm not worried about access attempts, as i know the chances are slim. but its the ammount of hits i get that is the problem.. last count for a 5 min spell was 87 hits.. in my eyes thats excessive.

i am wondering if anyone else has found this happening to them, as i can be sure that it wont just be one little laptop they are hitting on.

many thanks in advance
 
Old 02-06-2009, 06:41 AM   #2
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
If they're being refused, you have less to worry about. Probably the latest virus/trojan/rootkit is making new zombies and they're all testing your IP.

I have moved this to Security, so more knowledgeable people than I can see this.
 
Old 02-06-2009, 07:34 AM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Sorry, but your misspellings and abbreviations have made your post hard to read for me.
Quote:
ammount of m$ ip's
Are you saying that www.microsoft.com is the source IP?
 
Old 02-06-2009, 07:37 AM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Can you post a sample chunk from your firewall log?
 
Old 02-09-2009, 11:39 AM   #5
oodlebonse
LQ Newbie
 
Registered: Mar 2007
Posts: 4

Original Poster
Rep: Reputation: 0
sorry about my abbreviations, yes i mean microsoft, and yes they are being blocked, i am just curious as to why this would be happening, maybe it is the latest trojan or something probing ip's, i dont know, but unfortunately the logs are empty, so as soon as i have one to post i will.

many thanx

Last edited by oodlebonse; 02-09-2009 at 11:50 AM.
 
Old 02-09-2009, 12:22 PM   #6
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Without the IP addresses, protocols, and port numbers it is impossible to speculate. Please provide more details.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Get number of hits thisObject Linux - Software 3 05-11-2006 09:57 AM
ms-sql-m hits dareino Fedora 1 08-10-2005 04:57 AM
IPTables - Multiple Public IP's to private IP's matneyc Linux - Security 8 05-27-2005 12:23 PM
installed dropline, root loads kde3.2, user loads drop pgrimes Linux - Software 7 06-28-2004 06:11 PM
Massive Hits MrGreg Linux - Security 2 04-18-2001 09:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration