(Acces pirates)600 tentatives/j par 64.4.60.7
aladinobic
Messages postés
2
Statut
Membre
-
darkcrystal33 Messages postés 3815 Statut Contributeur -
darkcrystal33 Messages postés 3815 Statut Contributeur -
Bonjour,Suite a la detection de tentatives de piratage frequentes par Macaffee et conseillé judicieusement sur un autre forum, j ai reconfiguré mon systeme pour assurer la fermeture du maximum de ports et le moins de risques et j ai verifié sur grc.com l impermeabilite de ma machine.Ce jour je suis tres étonné de voir que Mcaffee detecte de facon continue une IP. 64.4.60.7 dénommée dav.bay0.hotmail.com, localisée sur un réseau a San Francisco, US et qui tente de facon systematique (2 fois par minute )d'acceder en changeant au numero de port suivant chaque fois . A 16h31, des que j ai allume ma machine , la tentative portait sur port 80/2054 et plus de 600 tentatives plus tard il en etait au port 80/2699 , exemple recent (copie de rapport du firewall 2006/06/20 00:23:16 64.4.60.7:80 (dav.bay0.hotmail.com) 192.168.1.15: port 2723 WatchDog NT. Pour le moment il ne semble y avoir aucun probleme sur ma machine et tous les scans ne detectent rien. Je serais heureux d avoir des commentaires d experiences similaires , et si un futé peut interprepter cela (est ce automatique par dfes serveurs malveillants ou s agit il d un malade qui a juré de passer a travers le firewall...?) et proposer une solution ( NB : j ai signalé a abuse@microsoft.com qui gere le réseau qu utilise le hacker) ou prevenir des risques encourus. Merci a l avance pour toute contribution.
A voir également:
- (Acces pirates)600 tentatives/j par 64.4.60.7
- Acces rapide - Guide
- Accès refusé - Guide
- Accès presse papier - Guide
- 600 heures en mois ✓ - Forum Excel
- Trousseau d'accès iphone - Guide
1 réponse
ton hacker est microsoft on dirait:)
***
WHOIS results for 64.4.60.7
Location: United States [City: Redmond, Washington]
Using 17 day old cached answer (or, you can get fresh results).
Hiding E-mail address (you can get results with the E-mail address).
OrgName: MS Hotmail
OrgID: MSHOTM
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 64.4.0.0 - 64.4.63.255
CIDR: 64.4.0.0/18
NetName: HOTMAIL
NetHandle: NET-64-4-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
NameServer: NS5.MSFT.NET
Comment: Abuse complaints will only be responded to if sent to
Comment: *****@microsoft.com and *****@msn.com.
RegDate: 1999-11-24
Updated: 2006-01-23
RTechHandle: MSFTP-ARIN
RTechName: MSFT-POC
RTechPhone: +1-425-882-8080
RTechEmail: ******@microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: *****@microsoft.com
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: ******@microsoft.com
# ARIN WHOIS database, last updated 2006-06-01 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
***
whois 64.4.60.7
[ Querying whois.arin.net ]
[ whois.arin.net ]
OrgName: MS Hotmail
OrgID: MSHOTM
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 64.4.0.0 - 64.4.63.255
CIDR: 64.4.0.0/18
NetName: HOTMAIL
NetHandle: NET-64-4-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
NameServer: NS5.MSFT.NET
Comment: Abuse complaints will only be responded to if sent to
Comment: abuse [AT] microsoft.com and abuse [AT] msn.com.
RegDate: 1999-11-24
Updated: 2006-01-23
RTechHandle: MSFTP-ARIN
RTechName: MSFT-POC
RTechPhone: +1-425-882-8080
RTechEmail: iprrms [AT] microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse [AT] microsoft.com
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: iprrms [AT] microsoft.com
# ARIN WHOIS database, last updated 2006-06-19 19: 10
# Enter ? for additional hints on searching ARIN's WHOIS database.
***
***
WHOIS results for 64.4.60.7
Location: United States [City: Redmond, Washington]
Using 17 day old cached answer (or, you can get fresh results).
Hiding E-mail address (you can get results with the E-mail address).
OrgName: MS Hotmail
OrgID: MSHOTM
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 64.4.0.0 - 64.4.63.255
CIDR: 64.4.0.0/18
NetName: HOTMAIL
NetHandle: NET-64-4-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
NameServer: NS5.MSFT.NET
Comment: Abuse complaints will only be responded to if sent to
Comment: *****@microsoft.com and *****@msn.com.
RegDate: 1999-11-24
Updated: 2006-01-23
RTechHandle: MSFTP-ARIN
RTechName: MSFT-POC
RTechPhone: +1-425-882-8080
RTechEmail: ******@microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: *****@microsoft.com
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: ******@microsoft.com
# ARIN WHOIS database, last updated 2006-06-01 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
***
whois 64.4.60.7
[ Querying whois.arin.net ]
[ whois.arin.net ]
OrgName: MS Hotmail
OrgID: MSHOTM
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 64.4.0.0 - 64.4.63.255
CIDR: 64.4.0.0/18
NetName: HOTMAIL
NetHandle: NET-64-4-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
NameServer: NS5.MSFT.NET
Comment: Abuse complaints will only be responded to if sent to
Comment: abuse [AT] microsoft.com and abuse [AT] msn.com.
RegDate: 1999-11-24
Updated: 2006-01-23
RTechHandle: MSFTP-ARIN
RTechName: MSFT-POC
RTechPhone: +1-425-882-8080
RTechEmail: iprrms [AT] microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse [AT] microsoft.com
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: iprrms [AT] microsoft.com
# ARIN WHOIS database, last updated 2006-06-19 19: 10
# Enter ? for additional hints on searching ARIN's WHOIS database.
***