| View previous topic :: View next topic |
| Author |
Message |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Wed Jan 30, 2008 7:43 pm Post subject: Proactive Alerts: Am I a bot? |
|
|
| Quote: | | Welcome to CastleCops®. Your IP address [x] matches our records for possible malicious activity observed on the Internet at 2008-01-27 08:03:36 UTC. If that IP address belonged to you, then we suggest you follow our Malware Removal and Prevention Procedures. If not, then this alert may not affect you. Contact administration to have the alert removed. This notice is in cooperation with {organization}, whose records are kept here in confidence at CastleCops. |
So we're teamed up with a few organizations and the idea materialized that we could use botnet data, etc, stored locally here at CastleCops and compare that to visitor IPs. All IP information stays on site. If your IP has been seen to conduct malicious activity on the Internet, we'll let you know. Here is what the current alert looks like (attached below).
Depending on the organization we're partnering to do this with, there may be a link to their site explaining in detail what was seen. For all alerts, we suggest stepping through our Malware Removal Prevention procedure:
http://wiki.castlecops.com/MRP
The IP list in its entirety will not be re-published here.
We're always looking to improve how we can make the world a better place, so feedback is always appreciated.
Thank you everyone.
|
|
| Back to top |
|
 |
Mister2
SRT Team Lead
 Premium Member
 Joined: Oct 28, 2004 Posts: 7329
|
Posted: Wed Jan 30, 2008 7:59 pm Post subject: |
|
|
That would be a great help to both site and visitor, and it sits well with the line below the notice: | Quote: | | making the world a better place |
I wonder if we should set up a separate forum solely for the purpose of requesting removal of an alert - either false alarms or after cleanup through MRP? Just thinking of the workload on Admin.  _________________ Never stop learning
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Cudni
Special Response Team
 Joined: Dec 10, 2002 Posts: 3717 Location: Et In Arcadia ego
|
Posted: Wed Jan 30, 2008 8:13 pm Post subject: |
|
|
This sounds like a great service to the community, could there be a little note or a link to explain how to establish or what it means that an ip address belongs to somebody?
Cudni _________________ Hecho en Mexico
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Cudni
Special Response Team
 Joined: Dec 10, 2002 Posts: 3717 Location: Et In Arcadia ego
|
Posted: Wed Jan 30, 2008 9:43 pm Post subject: |
|
|
sure, i'll draft something up
may we know what other organisation CC teamed up, or is that planned for later when links are established?
Cudni _________________ Hecho en Mexico
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
blacklupine
Captain
 Premium Member
 Joined: Mar 17, 2005 Posts: 484 Location: Over The Hills And Far Away!
|
Posted: Fri Feb 08, 2008 10:22 pm Post subject: |
|
|
Should you include an explanation as to the difference between a static and a dynamic IP address? Was thinking about visitors with a dynamic IP address who could get warnings relating to their current IP which had been used by another infected computer prior to them. They would then be under the impression that their computer was infected.
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
johnlgalt
Special Response Team Premium Member
 Joined: Feb 27, 2007 Posts: 1419
|
Posted: Wed Mar 12, 2008 12:20 am Post subject: |
|
|
Excellent - and I hope I *never* have to see tis message on any computer / network that I work on....
Of course, it will also help me work on said computers and networks - if I ever *do* see that message, the things come down and the cleaning begins. _________________ <img src="http://www.castlecops.com/zx/johnlgalt/johnlgalt%20sig.png">
<img src="http://www.castlecops.com/zx/johnlgalt/John%20L.%20Galt%20%20CPU-Z.png">
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, |