25 June 2013, 18:05
crsheltonTo site admin-possible security issue
When is accessed the Accurate reloading main screen, my Norton Utilities caught and neutralized a security threat; it was a Java intrusion and I will copy over and provide you with as much of the error message as I can:
Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
2013-06-25 7:56:32,High,An intrusion attempt by gribh.10faben.info was blocked.,Blocked,No Action Required,Web Attack: Malicious Java Download 13,No Action Required,No Action Required,"gribh.10faben.info (195.191.56.136, 80)",gribh.10faben.info/a702dc7b973f10d3e9d36f85c0a23089/68e0fecdb56b2aea182a6218e4cbc047.jar,"CRSHELTON-PC (192.168.1.106, 57555)",195.191.56.136 (195.191.56.136),"TCP, www-http"
Network traffic from <b>gribh.10faben.info/a702dc7b973f10d3e9d36f85c0a23089/68e0fecdb56b2aea182a6218e4cbc047.jar</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\JAVA\JRE6\BIN\JAVA.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.
I don't see it on my norton, but I'm checking the server for the file .jar. Also, te IP mentioned for the source of the attack is not our IP.
Don
25 June 2013, 23:31
Mike SmithThere is another site that uses accurate reloading but it is just slightly different from our url. If you mis-type it which I have done it takes you there. This might be the IP you are talking about.