A worm that kills the worm (notice high ping rates?)

http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

This goes after the worm AND the hole, kills and closes it, but ping rates are now WAY above normal.

Note the address localization:
The worm will select the victim IP address in two different ways. It will either use A.B.0.0 from the infected machine's IP of A.B.C.D and count up, or it will construct a random IP address based on some hard-coded addresses. After selecting the start address, it will count up through a range of Class C sized networks, for example, if it starts at A.B.0.0, it will count up to at least A.B.255.255.


Once it gets close to you, (from one random hit) things start getting worse quickly!

My firewall log is getting blasted!
 
Outpost 2.0 Pro - a nice firewall but for the inability to manage log file size!

I activated network card driver blocking to keep the logfile from growing too fast, and in about one hour, it's counted - 507

I do like my Intel 82558 based card with PRO drivers and Priority Packet - it can do basic packet dropping without bothering the firewall about it!

Mind you, it's broad brush, so unlike the firewall, it prevents me pinging out as well.
 
Last edited:
Well my son recently installed a Linux server for me with my 56k modem attached (dialup is all that I can get here :( ) running IPCop 1.30. In 5hrs yesterday, I got 1678 login attempts from 2 sites in China. Got 557 attampts the day before. In first 20min today, I already have 94 login attempts from the same 2 Chinese sites.

Thank God for Linux.
 
Top