home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

Immediate Help. network hijacked?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1526
Discussions: 200,506, Posts: 2,374,394, Members: 245,830
Old February 1st, 2005, 03:01 PM   Digg it!   #1 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,621
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Immediate Help. network hijacked?

I think i have a hijacked computer on my work network. My firewall has ALOT of traffic load and it is slowing down everything. I am having trouble pinpointing which computer it is coming from.

Any suggestions on what ports to look at? My firewall does not show who is producing the most load.

Any help would be great! I am on the verg of sutting down all client PCs.
__________________
"Life moves pretty fast, if you dont stop to look around once in a while, you could miss it." -FB
blubomber is offline   Reply With Quote
Old February 1st, 2005, 03:03 PM     #2 (permalink)
Real gangstas sip on Yacc
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Suckas-ville
Posts: 4,552
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
Your firewall doesn't have logging that shows where traffic coming from?

I would setup a computer and start sniffing traffic. See who is producing the problem traffic.

Jkrohn
jkrohn is offline   Reply With Quote
Old February 1st, 2005, 03:08 PM     #3 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,621
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
My firewall does keep a log of what traffic is going in and out, ports and IP addresses. And i am running Ethereal captures to try and pinpoint the PC. I guess this is just going to be a slow process?
blubomber is offline   Reply With Quote
Old February 1st, 2005, 03:31 PM     #4 (permalink)
Ultimate Member
 
elroy's Avatar
 
Join Date: Oct 2001
Location: Indiana
Posts: 3,764
If you are dealing with a limited number of machines disconnect them one at a time and see if the traffic pattern changes. If you have a thousand machines this might be a pain.
__________________
“Those who desire to give up freedom in order to gain security will not have, nor do they deserve, either one.”
Benjamin Franklin
elroy is offline   Reply With Quote
Old February 1st, 2005, 03:35 PM     #5 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,621
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Its a process of elimination.

I cut the VPN connection to one of my remote properties and all is good now at the main site. So i am off to the remote property (with fewer computers) to try and figure out the culprit there.

I will keep you up to date.

Thanks again for the help.
blubomber is offline   Reply With Quote
Old February 1st, 2005, 04:37 PM     #6 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,621
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Well, i am finding out more information as i go .

It looks like it is just a firewall problem. I have two watchguard Firebox IIIs connecting the two locations. The remote firebox, it appears, is overloading the VPN connection due to a programing bug. i am going to update it and see if that fixes my problem.
blubomber is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
if 90% believe it...can the braindead still say "conspiracy theory"? John Prophet IMO Community 218 October 30th, 2007 11:52 PM
Internet down but have net connectivity and valid ip address lunar Networking and Internet 11 February 23rd, 2005 03:28 PM
Airline Security - Is there a solution? brandon184 IMO Community 26 December 6th, 2004 08:12 PM
BUSH CONTINUES TO MISLEAD ABOUT 9/11 TOAD6147 IMO Community 31 March 12th, 2004 09:29 AM
Same web page no matter what address I type jamesy505 Networking and Internet 9 January 17th, 2004 05:23 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1635)
Review My Build (5)
FT HOOD attack: 7 killed 12 injured (66)
HELP!!! What do you think of this s.. (16)
Looking for a graphic card that wil.. (30)
Assosiations (21496)
My 1st pc build (40)
Aero in Vista (7)
PC Modern Warfare 2: it's much wors.. (12)
core i7 extreme 975, nvidia 9400gt (9)
How to Ship a PC (16)
Building my first computer (13)
slaving laptop drive (7)
[F@H SPAM 11/1/09]New month . . . n.. (33)
Recent Discussions
FAT32 to NTFS file system in Win2kpro (3)
Motherboards and my curse... (25)
Review My Build (5)
HELP!!! What do you think of this sys.. (16)
New Processor, Monitor will not turn .. (2)
2009 Build (4)
Internet very slow since updating AVG.. (7)
My 1st pc build (40)
Freezing During Music/Movies (1)
Windows Experience Index is screwed u.. (2)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
Help and Support disappeared from my .. (0)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)
wireless westell versalink model 327w (1)
New build 10 second reboot cycle! Won.. (3)
New Linksys Routers (2)
sometime power/Amber light (0)
Mic won't work. (2)


All times are GMT -4. The time now is 03:13 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28