What would you say this ISA log is saying?


Recommended Posts

Hi, I found the following in the firewall service log for ISA, this goes on for most of the day in the same periodic fashion.

ISAFirewallService.rtf

As you can see, 192.168.100.121 (workstation with apache on it for our SVN), tries to access 192.168.1.24, 192.168.1.22, 196.168.0.111, and 192.168.1.103. The problem is, our DHCP pool is from 192.168.1.100 to .255, meaning the IP's are part of a LAN, but not our LAN. (103 is dedicated to a WAN Miniport according to the DHCP manager). All the requests are on the SNMP port, 161.

During this time, I ran a tool from MS for interpreting event logs and it looks like someone was trying out a bunch of default usernames and passwords to get in; times corresponding to the events in the first log.

EventLockout.rtf

When i scan 192.168.100.121, 161 is not open, and the SBSSERVER only has 5 ports open, all which are needed and wouldn't interfere.

(SBSSERVER is running Exchange, ISA, WUS, AD, and is actign as a fileserver, as its an SBS2003 server; 192.168.100.121 is a workstation thats part of the domain managed by SBSSERVER).

WAN -> SBSSERVER (LAN) -> SWITCH -> WORKSTATIONS

Edited by JJ6829

Alright, ran a capture on the LAN and WAN interfaces.

On the LAN, the .121 was talking to the above IP's on TCP 9100 and then on SNMP (port 161 UDP). On the WAN interface, the 5 unknown IP's were somehow talking over SNMP again, but none of my other internal IP's had any entry in this capture.

I'm wondering about http://lists.virus.org/dshield-0302/msg00243.html though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft's fast coding model MAI-Code-1-Flash comes to Copilot Business and Enterprise by Karthik Mudaliar Microsoft’s recently announced MAI-Code-1-Flash model is now generally available to GitHub Copilot Business and Copilot Enterprise customers. With this support, organizations can have more centralized policy controls and billing while finally being able to use Microsoft’s lightweight, first-party coding model. According to GitHub’s announcement, Business and Enterprise plan administrators must enable the MAI-Code-1-Flash policy in Copilot settings before developers can access the model. Microsoft says that MAI-Code-1-Flash is for fast, iterative coding work rather than the most demanding architectural or debugging tasks. GitHub’s official model comparison page says that the model is great for "general-purpose coding and writing," while it excels at fast, accurate code completions and explanations Microsoft introduced MAI-Code-1-Flash on June 2 as part of a broader collection of internally developed MAI models. GitHub subsequently expanded support to Copilot CLI, the Copilot cloud agent, GitHub.com chat, GitHub Mobile, Visual Studio, JetBrains IDEs, Eclipse, and Xcode, but said support for managed Business and Enterprise customers was still on the way. In Microsoft’s own benchmark testing, MAI-Code-1-Flash scored 51.2% on SWE-Bench Pro, compared with 35.2% for Anthropic’s Claude Haiku 4.5. Microsoft also claimed that the model used up to 60% fewer tokens on SWE-Bench Verified. Do note that these are vendor-run results rather than independent measurements. The model is billed at provider list pricing under GitHub’s usage-based system. GitHub currently lists MAI-Code-1-Flash at $0.75 per million input tokens, $0.075 per million cached input tokens, and $4.50 per million output tokens. For organizations, the main incentive to use MAI-Code-1-Flash is likely to be efficiency rather than maximum capability. A smaller model that responds quickly and limits unnecessary output is quite useful for repetitive agent tasks at scale, especially after GitHub Copilot’s move toward usage-based billing. The "Flash" model is recommended for fast work and not necessarily for huge repositories with loads of context. It's better if teams compare their output with other larger models, especially if they're working on security-sensitive changes and complex, multi-file work.
    • yes AND no the "original" or plain/normal Optiplex 7010 won't be getting any more new firmware updates BUT the Optiplex SFF/SFF Plus {small form factor}, Micro/Micro Plus & Tower/Tower Plus 7010 editions DO get new updates such as this new one   and here are similar guides from the Dell web site for Dell systems: https://www.dell.com/support/kbdoc/en-us/000390990/secure-boot-transition-faq https://www.dell.com/support/kbdoc/en-us/000347876/microsoft-2011-secure-boot-certificate-expiration
    • AT&T has been spying on US citizens with the NSA for decades.. they just know how to keep it more under wraps.. the evil level is still there.
  • Recent Achievements

    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      444
    2. 2
      +Edouard
      200
    3. 3
      PsYcHoKiLLa
      155
    4. 4
      FloatingFatMan
      71
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!