What would you say this ISA log is saying?


Recommended Posts

Hi, I found the following in the firewall service log for ISA, this goes on for most of the day in the same periodic fashion.

ISAFirewallService.rtf

As you can see, 192.168.100.121 (workstation with apache on it for our SVN), tries to access 192.168.1.24, 192.168.1.22, 196.168.0.111, and 192.168.1.103. The problem is, our DHCP pool is from 192.168.1.100 to .255, meaning the IP's are part of a LAN, but not our LAN. (103 is dedicated to a WAN Miniport according to the DHCP manager). All the requests are on the SNMP port, 161.

During this time, I ran a tool from MS for interpreting event logs and it looks like someone was trying out a bunch of default usernames and passwords to get in; times corresponding to the events in the first log.

EventLockout.rtf

When i scan 192.168.100.121, 161 is not open, and the SBSSERVER only has 5 ports open, all which are needed and wouldn't interfere.

(SBSSERVER is running Exchange, ISA, WUS, AD, and is actign as a fileserver, as its an SBS2003 server; 192.168.100.121 is a workstation thats part of the domain managed by SBSSERVER).

WAN -> SBSSERVER (LAN) -> SWITCH -> WORKSTATIONS

Edited by JJ6829

Alright, ran a capture on the LAN and WAN interfaces.

On the LAN, the .121 was talking to the above IP's on TCP 9100 and then on SNMP (port 161 UDP). On the WAN interface, the 5 unknown IP's were somehow talking over SNMP again, but none of my other internal IP's had any entry in this capture.

I'm wondering about http://lists.virus.org/dshield-0302/msg00243.html though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I have a Motorola, one of the lower end ones, it works fine. It is possible to get rid of the Gemini app and also to disable googles assistant , but A.i is still apps. I try to avoid all LLM A.I, is i can, I use no Ai duck duck go.
    • Free Software Foundation Europe pushes EU to force Google to allow AI uninstalls on Android by Paul Hill Credit: Pexels Users should be able to fully uninstall AI-based features from Android devices and be able to access interoperability functions, free from Google’s verification requirements, the European Commission has heard as part of an Android interoperability consultation under the Digital Markets Act. These measures were proposed by the Free Software Foundation Europe (FSFE) last week when it submitted its documentation. The FSFE noted that Google had started silently installing AI models without telling users. It noted that the EU’s DMA requires companies like Google to allow users to uninstall pre-loaded software from their devices, but in the case of the AI models Google is installing, they reinstall if you delete them, contravening the DMA. To get Google back under control, the FSFE has told the European Commission that there needs to be improvements within the Android Open Source Project (AOSP). First, it said that users should be able to fully remove pre-loaded AI components from their devices, with companies being prohibited from silently reinstalling or reactivating them. Second, access to Android interoperability features should not be contingent on registration, authorization, or contractual relationships with Google. This pertains to Google’s attempt to force developers to register with Google, even to publish apps to alternative app stores like F-Droid. Discussing its submission, Lucas Lasota, FSFE Legal Programme Manager, said: Google is planning to roll out its Android Developer Certification in September 2026. This will force every Android app developer to register with Google before their software can be installed on certified Android devices, but it should affect those who have removed Google Apps from their device. The program is controversial because it entails the signing of contracts and payment of account fees to Google, as well as the handing over of the identities of developers. It said: The FSFE said that if the Commission’s draft measures remain unchanged, then Google will be allowed to make developers verify their identity. The FSFE believes that asking developers to register is contrary to the text and spirit of the law. In summary, the FSFE has told the Commission that no developer should need a Google account, a Play Store presence, or any agreement with Google to access Android’s interoperability features.
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      188
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      72
  • Tell a friend

    Love Neowin? Tell a friend!