Click here to get back home

hacker attempts?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
hacker attempts? will~ 06-13-2007
`--> Re: hacker attempts? Roger Abell [MV...06-14-2007
Posted by will~ on June 13, 2007, 10:10 am
Please log in for more thread options
Windows 2003 Server R2 standard edition with SP2, sitting behind SonicWall
firewall.

Recently, there are a lot of Alerts from SonicWall. Such as "IPSec
Authentication Failed" and "IPSEC Replay Detected" and some "Sub Seven Attack
Dropped"

It appears that the source IP address causing the IPSec Authentication
Failed messgae is from the same source IP address. I do not recognise this
IP address and upon checking the internet it seems to be originated from
another town.

The fact that these are logged in sonicwall shows these have been detected.
However, please advice if these IP addresses can be blocked from within
windows server, so that in the event that they have gone past the firewall
they could not establish communication with the server?

If these are hacking attempts are there any authority that we can report to?
Many thanks for your assistance.





Posted by Roger Abell [MVP] on June 14, 2007, 1:34 am
Please log in for more thread options
It is pretty hard to go from "something at this IP is sending packets to me"
to saying "I am getting hack attempts from this IP". Without the ability to
establish that going to the second is clearly valid, there is nothing one
can do, and even with it whether anything can be done usually depends
on the good will of those with the network where that IP lives.

You might want to search the MS website for the guidance on
using IPsec for "domain isolation".

Roger

> Windows 2003 Server R2 standard edition with SP2, sitting behind SonicWall
> firewall.
>
> Recently, there are a lot of Alerts from SonicWall. Such as "IPSec
> Authentication Failed" and "IPSEC Replay Detected" and some "Sub Seven
> Attack
> Dropped"
>
> It appears that the source IP address causing the IPSec Authentication
> Failed messgae is from the same source IP address. I do not recognise
> this
> IP address and upon checking the internet it seems to be originated from
> another town.
>
> The fact that these are logged in sonicwall shows these have been
> detected.
> However, please advice if these IP addresses can be blocked from within
> windows server, so that in the event that they have gone past the firewall
> they could not establish communication with the server?
>
> If these are hacking attempts are there any authority that we can report
> to?
> Many thanks for your assistance.
>
>
>
>



Similar ThreadsPosted
Redial attempts November 4, 2005, 11:52 pm
Continuous Login Attempts May 13, 2008, 12:19 pm
Hundreds of failed login attempts March 30, 2006, 1:13 pm
blocking brute force login attempts November 26, 2007, 2:09 pm
Hacker October 11, 2007, 3:34 pm
Hacker locking my accounts March 16, 2008, 5:02 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap