Wow ! More & more complaints on this issues - and most from India. Odd, that this worm doesnt affect gateways in other countries.
Everah wrote:
How can an ISP not protect their equipment enough to allow something like this to happen?
First of all, most ISPs here provide internet through a local cable operator as a gateway and most of these gateways are on Windows - not Linux. And I wont be surprised if its running on WinXP or Win2000. Linux at the local customer-level is still a long way.
chillpill_rohit wrote:
and im a part of a local area network hosted by a local cable operator
From Nerul here and same setup - using Sify though.
chillpill_rohit wrote:
ME and our cable operator had no clue that its such a big problem only after reading your blogs
I can never seem to talk to my cable operator in such depths. I can understand that he has no clue as to whats going on - because he keeps saying "
हां । काम हो रहा है । पांच मिनट में आजाएगा"
chillpill_rohit wrote:
1. The net never disconnects at nite... arnd after 10pm till early in the morning arnd 8 or 9am when usually offices start...i got many office networks inside my local area network.
Not all the time - even at night I face same issues - guess some PC is still on at the time. But often I have noticed smooth connectivity during the night. But also a request timed out.
chillpill_rohit wrote:
2. Whenever net disconnects i ping to my gateway 172.25.0.1 and i get request timed out but thn at the same time if i ping to sum1 else on my network eg : 172.25.3.120 or 172.25.3.39 (rather they r dead or alive)
my ping to gateway 172.25.0.1 immediately starts responding and the net starts working as normal........again if it gets disconnected i do the same procedure.......
This is news to me. Unfortunately I dont know any IPs in my network (its going to be tedious to try all out)
I have Apache httpd 2.2.6 on my WinXP PC and I keep checking the access & error log files.
Quite often I get a request from a local IP
- 10.12.165.90 - - [14/Jan/2008:22:45:52 +0530] "OPTIONS / HTTP/1.1" 200 -
- ....
- 10.12.165.133 - - [15/Jan/2008:20:56:38 +0530] "OPTIONS / HTTP/1.1" 200 -
- ...
- 10.12.165.133 - - [18/Jan/2008:10:50:36 +0530] "OPTIONS / HTTP/1.1" 200 -
Tried these IPs with your method of pinging them if ping <gateway> times out. Doesnt seem to work.
This might have worked 2-3 weeks back, right now the ISP or cable guys are upto something. I keep getting timed out at random intervals - all the time. Never steady enough to download a 5MB file @256kbps.
chillpill_rohit wrote:
3. I have observed tht whenever my net gets connected the first site i get redirected to is
http://g.asdafdgfgf.com/ads.js which u all r talking abt....
Redirect ? Are you sure ? I never got redirected. All my pages got injected with that JS line on top and tried to pull that JS file first. I hope thats what you meant by redirect.
chillpill_rohit wrote:
2. Intrusion frm local network ... that is frm the PCs in my network which dont have proper antivirus and in which tht javascript is residing and continuously addressing the gateway 172.25.0.1 which we all share in our ip range......so the point is due such few infected PCs which i found are OFF during night time( when net works perfectly fine)......
This may be true, but because of the randomness, its quite difficult to know. But what I dont understand is, how can a PC in the network send the html page to the gateway and then send it to the users. Shouldnt it be the other way round - gateway sends data to PCs and on the way one the infected PCs injects that JS line to other destined PCs - I suck at networking, but I thought this was how point-to-point works.
chillpill_rohit wrote:
but wat remains is the internal attack which still is cloggin the gateway .........to solve this we have asked all the users in my ip range to install Nod32 or Norton to secure there PCs so tht it doesnt allow such scripts to run on their PCs and congest the gateway...........
Its the firewall thats required more than the anti-virus. But most cost which ppl wont buy.
Im still facing terrible slowness. Unfortunately Im residing in an are awhere Sify dominates - recently Tata Indicom lines were established. YouTeleCom is not available in all sectors. Other major players like AirTel etc arent available in Navi Mumbai.
Luckily your ISP 'listens' to you. When I called tech support, and when the exec inquired at the higher level, the reply was always 'contact your hardware engineer' (to check for virus etc) !