What would you say this ISA log is saying?


Recommended Posts

Hi, I found the following in the firewall service log for ISA, this goes on for most of the day in the same periodic fashion.

ISAFirewallService.rtf

As you can see, 192.168.100.121 (workstation with apache on it for our SVN), tries to access 192.168.1.24, 192.168.1.22, 196.168.0.111, and 192.168.1.103. The problem is, our DHCP pool is from 192.168.1.100 to .255, meaning the IP's are part of a LAN, but not our LAN. (103 is dedicated to a WAN Miniport according to the DHCP manager). All the requests are on the SNMP port, 161.

During this time, I ran a tool from MS for interpreting event logs and it looks like someone was trying out a bunch of default usernames and passwords to get in; times corresponding to the events in the first log.

EventLockout.rtf

When i scan 192.168.100.121, 161 is not open, and the SBSSERVER only has 5 ports open, all which are needed and wouldn't interfere.

(SBSSERVER is running Exchange, ISA, WUS, AD, and is actign as a fileserver, as its an SBS2003 server; 192.168.100.121 is a workstation thats part of the domain managed by SBSSERVER).

WAN -> SBSSERVER (LAN) -> SWITCH -> WORKSTATIONS

Edited by JJ6829

Alright, ran a capture on the LAN and WAN interfaces.

On the LAN, the .121 was talking to the above IP's on TCP 9100 and then on SNMP (port 161 UDP). On the WAN interface, the 5 unknown IP's were somehow talking over SNMP again, but none of my other internal IP's had any entry in this capture.

I'm wondering about http://lists.virus.org/dshield-0302/msg00243.html though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

  • Recent Achievements

    • Week One Done
      davidbazooked earned a badge
      Week One Done
    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      PsYcHoKiLLa
      185
    3. 3
      +Edouard
      159
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!