Virus On Military Network

言語: JP EN DE FR
2010-06-21
New Items
users online
フォーラム » Everything Else » Tech Support » Virus on military network
Virus on military network
 Ramuh.Krizz
Offline
サーバ: Ramuh
Game: FFXI
user: Krizz
Posts: 23561
By Ramuh.Krizz 2009-12-04 16:17:36  
Ok, serious question for you folks. Particularly those in IT fields.

Today we've had a site calling up telling us they have a virus that fills up the HD.

According to our network administration (who sucks, btw), the problem is a isakmp.log file. The program IreIKE.exe is filling it up.

Now this program / log is part of VPN software running on all the computers.

So far the only solution we have thought of or found is a system restore to a previous date. We have no idea what is causing this problem. My thoughts is that it could be a configuration error or obviously a virus.

Unfortunately I don't have a machine here locally with the virus to do hands on troubleshooting.

Anyone heard of this?

Edited at 1800 to clarify the number of sites. Only one confirmed with this problem. The others were different issues.
[+]
 Seraph.Caiyuo
Offline
サーバ: Seraph
Game: FFXI
user: Caiyuo
Posts: 6524
By Seraph.Caiyuo 2009-12-04 16:52:22  
Well, initially if it's a .log file that's rapidly gaining in size I'd first think that some machine/server/router is either spamming error notices or was left in Debug mode when previously trying to fix something and as such is having all the of the network activity for those particular protocols being written to log files.

The specifics would be better left to the Admin as far as what's happening with the security VPN software and protocol you're using, but a really similar situation occurred in a completely unrelated way when an IP-blocking program I'd used was set to write and archive all logs for allowed and blocked IPs once a day and suddenly 19GB vanished! lol
 Ramuh.Lilbusta
Offline
サーバ: Ramuh
Game: FFXI
user: phatspade
Posts: 4580
By Ramuh.Lilbusta 2009-12-04 17:22:57  
Well from some of the things I've read about that log file is if someone was trying to connect to your network it would log it. For that log to fill the whole HDD in minutes would be quite a bit of machines trying to access that VPN at the same time similar to a DoS attack.
 Asura.Korpg
Offline
サーバ: Asura
Game: FFXI
user: Korpg
Posts: 7782
By Asura.Korpg 2009-12-04 17:27:58  
yay for somebody hacking into our military network so they can launch some nukes -.-
 Hades.Hiryo
Offline
サーバ: Hades
Game: FFXI
user: Hiryo
Posts: 362
By Hades.Hiryo 2009-12-04 18:00:24  
And so it begins!


Hello Skynet!


Goodbye world!
 Ramuh.Krizz
Offline
サーバ: Ramuh
Game: FFXI
user: Krizz
Posts: 23561
By Ramuh.Krizz 2009-12-04 18:16:29  
Whenever files are deleted, the log file expands to fill that space.

This tells me that it's not a DOS/DDOS attack. It's most likely what Caiyuo said as far as some sort of configuration gone screwy.

Like I said, I don't have a machine to personally troubleshoot at my location.
 Gilgamesh.Andras
Offline
サーバ: Gilgamesh
Game: FFXI
user: Andras
Posts: 705
By Gilgamesh.Andras 2009-12-04 20:52:47  
Hades.Hiryo said:
And so it begins!


Hello Skynet!


Goodbye world!

better start preparing for the end of the world... to bad robots are hard to fight... fml...
Log in to post.