home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

Immediate Help. network hijacked?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1526
Discussions: 200,903, Posts: 2,378,872, Members: 246,272
Old February 1st, 2005, 03:01 PM   Digg it!   #1 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Immediate Help. network hijacked?

I think i have a hijacked computer on my work network. My firewall has ALOT of traffic load and it is slowing down everything. I am having trouble pinpointing which computer it is coming from.

Any suggestions on what ports to look at? My firewall does not show who is producing the most load.

Any help would be great! I am on the verg of sutting down all client PCs.
__________________
"Life moves pretty fast, if you dont stop to look around once in a while, you could miss it." -FB
blubomber is offline   Reply With Quote
Old February 1st, 2005, 03:03 PM     #2 (permalink)
Real gangstas sip on Yacc
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Suckas-ville
Posts: 4,552
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
Your firewall doesn't have logging that shows where traffic coming from?

I would setup a computer and start sniffing traffic. See who is producing the problem traffic.

Jkrohn
jkrohn is offline   Reply With Quote
Old February 1st, 2005, 03:08 PM     #3 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
My firewall does keep a log of what traffic is going in and out, ports and IP addresses. And i am running Ethereal captures to try and pinpoint the PC. I guess this is just going to be a slow process?
blubomber is offline   Reply With Quote
Old February 1st, 2005, 03:31 PM     #4 (permalink)
Ultimate Member
 
elroy's Avatar
 
Join Date: Oct 2001
Location: Indiana
Posts: 3,764
If you are dealing with a limited number of machines disconnect them one at a time and see if the traffic pattern changes. If you have a thousand machines this might be a pain.
__________________
“Those who desire to give up freedom in order to gain security will not have, nor do they deserve, either one.”
Benjamin Franklin
elroy is offline   Reply With Quote
Old February 1st, 2005, 03:35 PM     #5 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Its a process of elimination.

I cut the VPN connection to one of my remote properties and all is good now at the main site. So i am off to the remote property (with fewer computers) to try and figure out the culprit there.

I will keep you up to date.

Thanks again for the help.
blubomber is offline   Reply With Quote
Old February 1st, 2005, 04:37 PM     #6 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Well, i am finding out more information as i go .

It looks like it is just a firewall problem. I have two watchguard Firebox IIIs connecting the two locations. The remote firebox, it appears, is overloading the VPN connection due to a programing bug. i am going to update it and see if that fixes my problem.
blubomber is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
if 90% believe it...can the braindead still say "conspiracy theory"? John Prophet IMO Community 218 October 30th, 2007 11:52 PM
Internet down but have net connectivity and valid ip address lunar Networking and Internet 11 February 23rd, 2005 03:28 PM
Airline Security - Is there a solution? brandon184 IMO Community 26 December 6th, 2004 08:12 PM
BUSH CONTINUES TO MISLEAD ABOUT 9/11 TOAD6147 IMO Community 31 March 12th, 2004 09:29 AM
Same web page no matter what address I type jamesy505 Networking and Internet 9 January 17th, 2004 05:23 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2799)
Is the PSU I received dead? (10)
Install XP pro and a Vista laptop ?.. (7)
California Passes Anti-Flat-HDTV Le.. (38)
A good PSU? (10)
Foreign voltage (5)
New Computer wont recognize XP disc (7)
Fox uses old news clips to inflate .. (33)
HIS HD5770 graphic card question (10)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Print spooler problem (5)
EVGA 9800 gtx help with finding a g.. (6)
Ideal cheap graph card for PC-Gamin.. (13)
Mysterious Boot manager (9)
Recent Discussions
Need hard disk drivers (3)
Cloning old drive to new drive (6)
Asus P4G8X Mobo (0)
Amptron monitor G17FP-Black (0)
windows vista security holes (0)
EVGA 9800 gtx help with finding a goo.. (6)
A good PSU? (10)
Install XP pro and a Vista laptop ?? (7)
Is the PSU I received dead? (10)
Ideal cheap graph card for PC-Gaming? (13)
HP Pavillion Laptop ze4220 won't turn.. (7)
HIS HD5770 graphic card question (10)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Foreign voltage (5)
Convert 5 pin Keyboard to USB (11)
Print spooler problem (5)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)
World's largest Monopoly Game using G.. (328)
Modern Warfare 2: Who Bought It? (60)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (28)
blender help (2)
Hard drive freezes boot (1)
Mysterious Boot manager (9)


All times are GMT -4. The time now is 01:19 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28