i can't access internet after i scan for viruses using smadav and avastwhen i type sonfig /all in CMD, here are the resultsWindows IP Configurationan internal error occurred : the request is not supportedAdditional information : Unable to query host name
I have an 5510 running 8.4(1) I can ssh into the system with no problems until I scan the device with Nessus security scanner. After that I just get timeouts from the client when I try to connect and the only way to fix the problem is to reload the device. I have included 2 syslog dumps one showing ssh into the device before(working) the scan and one after(not working).I do not have any acls on that int and I have turned off basic threat detection. The devices is still running I can login via the serial console and via ASDM it just appears ssh is someone shutdown or hung.
WORKING
4/21/2011 11:33:43 AM 192.168.11.108 Debug %ASA-7-609002: Teardown local-host testing:192.168.65.106 duration 0:00:104/21/2011 11:33:43 AM 192.168.11.108 Informational %ASA-6-302014: Teardown TCP connection 50 for testing:192.168.65.106/4462 to identity:192.168.11.108/22 duration 0:00:10 bytes 3691 TCP Reset-O4/21/2011 11:33:43 AM 192.168.11.108 Informational %ASA-6-315011: SSH session from 192.168.65.106 on interface testing for user "test" terminated normally4/21/2011 11:33:40 AM 192.168.11.108 Informational %ASA-6-605005: Login permitted from 192.168.65.106/4462 to testing:192.168.11.108/ssh for user "leeh"4/21/2011 11:33:40 AM 192.168.11.108
[code]....
NOT WORKING
4/21/2011 12:38:17 PM 192.168.11.108 Informational %ASA-6-302014: Teardown TCP connection 86 for testing:192.168.65.106/1954 to identity:192.168.11.108/22 duration 0:05:01 bytes 0 Connection timeout4/21/2011 12:38:17 PM 192.168.11.108 Debug %ASA-7-609002: Teardown local-host testing:192.168.65.106 duration 0:05:014/21/2011 12:33:15 PM 192.168.11.108 Debug %ASA-7-609001: Built local-host testing:192.168.65.1064/21/2011 12:33:15 PM 192.168.11.108 Informational %ASA-6-302013: Built inbound TCP connection 86 for testing:192.168.65.106/1954 (192.168.65.106/1954) to identity:192.168.11.108/22 (192.168.11.108/22)
So I have this ancient Linksys WRT54G router that got a virus, at least I am 99% certain that is the case. i would come home once a week and it would be reset to factory default. Any device going through it would have DNS re-directs to sites filled with spyware. If I used someone elses wireless there were no problems. I dumped the router for a cheapy and all is well again.
So my question, is how did it get this virus and how can I prevent it from happening again? I did try upgrading the firmware but didn't solve my problems.
OK- so my computer was going haywire - freezing, lagging, crashing. Only thing I could do was to restart in safe mode and run a full AVG scan which did show viruses that were sent to virus vault. Once I restarted into normal windows mode, the computer seems to be working fine with no freezing, etc.....but my LAN connection won't work. Looking at all the device managers and info on the LAN - it says "device is working properly". I have tried downloading a few "fix it" programs like Winsockxpfix and Complete Internet Repair - didn't work.
So we had a PCI scan, and we failed on a couple things where the devices are HP printers.For those that don't know, PCI = Payment Card Industry
Quote:
service tcp 34862 Linux nfs-utils Overflow
The rpc.mountd service was detected on this server. This is a remote procedure call (RPC) based service that is known to have an overflow vulnerability which can give root-level access to an attacker. Note that this service may have been activated by default when you installed your operating system.
Quote:
service udp 2049 RPC nfsd Detected
The nfsd program faciliates the Unix Network File System, which is rarely meant to be exposed to the public Internet. Many Unix/Linux systems activate a number of RPC services by default during installation. The nfsd program has also had vulnerabilities which could allow an attacker to gain control of this system.
Quote:
Windows Registry Accessible The Windows Registry is accessible by remote users and can be accessed using a NULL session (no credentials) or using the built-in Guest account. The Registry is a critical collection of information that governs how Windows and installed applications operate. The Registry is a primary target for attackers to view or modify.
These 3 came from an HP LaserJet M4345 MFP.What needs to be disabled? Strangely, the other M4345's didn't get these. I compared configurations, but everything was the same that I could see (except for the SNMP setting).
Get "router/acess point channel conflict error and when I try Epson scan icon it tells me it cannot communicate with scanner.When I reinstalled CD, it told me the installation failed as some files necessary fo set up were missing.
the setup is as follow: I have two separate network.192.168.90.xx and 10.10.xx.xx the two boxes being connected via an ethernet cable. How would I go about having a 192.(...) machine speak to a 10.(...) box? My boss tells me that via a UDP call the 192.(...) machine can get the IP of a 10.(...) box. Isn't UDP dependant on a subnet mask to limit the # of queries, and in that case would it even be feasable? I was thinking instead of spoofing the 192.(...) IP to an unoccupied 10.(...) IP. Of course to do this would require knowing what IPs are unoccupied on the other network, and I cannot assume the would respond to pings.
I am trying to use Nmap to determine whether a certain IP address is available or not. However, the output of the scan shows that it scanned the subnet my computer is on and only one address in the network I typed in (MPLS network). Is there any way I can have Nmap only scan that one subnet and not all the others?
keep getting this message from my firewall:A port scan was detected. Local IP:192.168.xxx Remote IP: 192.168.1.xxx. Protocol: UDP.Action Taken: BlockedWhat does this mean?!!? And what effect will it have? Simple question for pro's.
I put my laptop in safe mode w/ networking and started to run Microsoft safety scanner, then when the scan is almost finished the whole thing shuts down.
I'm on my 3rd Virgin media 615 today, the last one arrived yesterday and I opened the box to fine a rev d with old bios installed, throw hands in air and all that and then proceeded to upgrade to 4.13 which I have found to be stable and work ok, the other two grow to have the wireless failure issue, I could moan here about VM but hey there's no point so I have come here for adviseafter I found the last one wireless going down, daily trips from the kids down to me to ask why the internet isn't working etc etc I started to investigate, I found the 4.13 and gened up a bit, looked at the 3rd party code and came back to Dlinks own code, anyway I have seen in the last few days hundreds of similar port scans. [code]
Now is the the router being a little sensitive to harmless software companys scans to see if products installed etc or are they something to worry about now I know whats going on if its the latter, and I don't think anyones got in yet but I would like to ban these ip's and to be honest I'm not sure of the best way also I noted a UDP active session that not a part of my subnet too mine being a standard 192.168.0.*and the other being 192.168.4.*.
When I look at the local area connection the status is acquiring network address and just sits there. When I try to repair, it states that windows couldn't finishing repairing because it can't renew my IP address.
I'm running Windows 7 Pro. I noticed tonight when I clicked on Network in Windows Explorer that in addition to my home PCs there is a PC with someone's name on it. My suspicion is that my wireless ISP has screwed up in some way. I ran SoftPerfect's Network Scanner and don't see any strange IP addresses, so this stranger's PC is not on my subnet. What tools are available to scan my network and give me more info about the stranger's PC?
My pc is windows xp an has service pack 3, the adaptor is realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC. I have 3 gig of memory and a very larg nvidia card. OK my pc has worked absolutely fine until this weekend when my sister came and her son was on my pc when everyone was in bed. He attempted to print of not less than 88!! pictures he had acquired from different sites but i had disconnected the printer so it didnt take place. When they left earlier today i switched on my pc and there was a virus alert so i ran a scan. These got put into the chest. I then attemtpted to close down the programmes that had come back up when i switched on and this is when it happened. The pc told me it was going to shut down and when it restarted i had not internet connection. I checked the modem and the ethernet light is out.
I have a dell 2155CDN network printer I want to scan files over the network when I scan once it finishes I get a SMB List error and the file does not go trough here is a picture of my settings?
I have a dir-655 Firmware Version 2.00, hardware:B1 It's a new wireless router and it's just a week ago I got it.My problem is that the wireless is just stopping to work, it just disappear.When I do a rescan of wireless AP's the ssid and my AP is not showing up.I have to reboot the router the hard way by unplugging the power source.I have multiple computers and wireless devices, and they all loose connection and no one even see the ssid (AP) defined on my dir-655.It's connected to a cable modem switch (without nat), I'm running dhcmp on my router. No Qos engine is enabled.This happens when I'm working from home with a VPN tunnel from my pc to my companies network.I've tried to make a ticket on this on dlink support pages, but their support system only works on IE7, and the password is anyway rejected. how to solve the termination of my wifi ap?
As part of my business' PCI compliance regime, we are regularly scanned for vulnerabilities. Today we started getting notifications of failure on all of the QuickVPN ports (443, 60443) for the following:
06/11/12 CVE 2009-3555 Multiple vendors TLS protocol implementations are prone to a security vulnerability related to the session-renegotiation process which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context.
Cisco, will you be issuing a firmware update to address this anytime in the near future? Presumably it effects all the other RV routers as well.
Connected our Brother MFC-8820D printer/scanner/fax directly to one of the 4 Ethernet ports on the back of the DIR-655 in our new install with this router, and all computers can print to it, whether connected via an Ethernet cable or via wireless, but none of the printers can scan. We just get an error message. Scanner driver is installed on all computers. Same printer worked fine via Ethernet on a Windows small business server for printing and scanning. Windows server no longer used or connected. Only DIR-655 as we are dumbing down and getting rid of our Windows server and have gone to a NAS solution connected to the DIR-655.
What can we do to make the scanning work on our Multifunction printer?
I'm currently investigating an issue for one of our customers where one of their 3750 Core Switch Stacks crash / becomes unresponsive during a NESSUS Scan.
They've diabled DoS testing and have ensured that safe scanning is enabled. For the test they are port scanning all of their VLANs (around 600 internal addresses).
The network consists of 2x 3750 Switch Stacks connected via fiber, edge switches connect into these cores. Both cores are running HSRP, for VLAN gateway redundancy.
Issue Being faced is as follows:
During the scan, Core 1 becomes unreachable from Core 2. We can telnet to Core 2 and administer as necessary. However we cannot telnet to Core1, a console connection also fails - the switch stack is unresponsive, but does respond to pings.
On Core 2 I've performed a show proc cpu sorted and can see the IP Input process is running at around 60% and the CPU is highly utilised.
Once Core 1 becomes unreachable the network gradually grinds to a halt, almost mimicking some sort of broadcast storm or Spanning Tree loop.
Interestingly Core 1 HSRP is still active, so the hello packets are still being sent.
The only resolution to the issue is to perform a hard reset of the Core to restore service.
Logs from core 1 show the CPU becomes fully utilised. There is also an error logged indiciating:
%FIB-2-FIBDOWN: CEF has been disabled due to a low memory condition. It can be re-enabled by configuring "ip cef [distributed]"
Both cores are running IOS 12.2.(52) SE IPBASE. I've attempted to reproduce the issue in the office here and although a NESSUS scan does increase switch CPU utilisation I couldn't reproduce the failure scenario.
What may be causing the 1st core to become unresponsive? I've found some articles with regard to a 6500 switch rebooting during a NESSUS scan, and also some HP switches exhibiting similar behaviour but nothing that matches the exact scenario I'm investigating.
I have studio 1737, With my Intel WiFi 5100 AGN. I also instaslled latest drivers but when i want to scan for any wireless network it says adapter not found.