Just curious

RWBRWB Icrontian
edited January 2007 in Spyware & Virus Removal
I am able to see the traffic sent on our networks, basically what IP's and Ports guests at our hotels are trying to connect to. Occasionally we get guests that are blasting traffic seemingly random through a ton of IP's and all kinds of ports, all just random. This causes issues on the server when the log fills up, and pings get high and occasionally the server stops responding to even a ping and we have to have the hotel unplug the subscriber port.

I am curious if anyone knows if this is a specific virus or what? I just spoke with a guest and he's barely passing traffic but these requests are slowing the server down so I had to ban him. He had Trend Micro AV and Spysweeper, neither seemed to pick anything, they were both updated.

Naturally I am not at the guests computer and I am no longer on the phone with him so troubleshooting further won't do. I am just kinda curious if anyone has any ideas? One thing I didn't think of is bit torrent or something like that... but then wouldn't bit torrent be going out of the same port? And more traffic...

This isn't much, but he had like 36 processes and CPU utilization was normal.

Comments

  • jmoney3457jmoney3457 Maine
    edited January 2007
    hi RWB, it very well could be...many malware's are capable of this, not knowing what's on there though, have you done a complete network virus(malware) scan?
  • RWBRWB Icrontian
    edited January 2007
    Well the hotel has about 50 other users all normal, when removing this particular person it resolved the issues of slow throughput/high pings on the server. It's also Linux based server, that doesn't make it full proof though.

    I got in today and checked the server, I removed the guest from our filter. It would seem he figured it out because all is good now. Though as soon as that was resolved, another guest started cuasing issues. But this time I could see it was all going to a specific address over port 5190, which is a known port for a virus that does a DDOS attack on a list of servers. Banned him, gtg. haha. I haven't ever had to ban people this often before, especially for one friggin site. We have like 70-80 hotels. Before this I think I banned someone like 4 months ago.
  • jmoney3457jmoney3457 Maine
    edited January 2007
    glad you banned person responsible for the DOS attack:) ..can I mark this thread resolved now?:D
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited January 2007
    Probably Mytob infecting port 5190. Stupid AIM.
  • TroganTrogan London, UK
    edited January 2007
    Jmoney,

    I don't see a reason for this thread to be closed, unless RWB wants it to be.
  • jmoney3457jmoney3457 Maine
    edited January 2007
    yes sir trog:D
Sign In or Register to comment.