icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » Reseller Hosting » Access from work issue

Reseller Hosting Questions about your reseller hosting account.

Reply
 
LinkBack Thread Tools Search this Thread
Old May 29th, 2007, 8:05 PM   #1 (permalink)
Surpass Fan
On a golden path...
 
sneagle's Avatar
 
Joined in Oct 2005
Lives in Northern NJ
Hosted on PASS83
332 posts
Gave thanks: 6
Thanked 16 times
Access from work issue

I cannot access my website nor Surmunity from work.

This started after a virus outbreak and tightening of security and the firewall. Today, I ran into one of the network operations people and asked "WHY?" He investigated and said
Quote:
They "seem" to be infected with the Nirbot virus. The rule that is stoping the site is the rule that stops the morphing of the Nirbot virus.
Nirbot - Also known as: W32/Delbot (Sophos), W32.Rinbot (Symantec), Backdoor.Win32.VanBot (Kaspersky) - it seems to work through port 8080
http://www.symantec.com/outbreak/w32.rinbot-worm.html

Now I doubt Surpass is infected with a virus, so I am hoping that I can learn something to convince the network folks to allow me access. I posted here first rather than a ticket to Support to get the learned opinion of Surmunity before I went to support.

So, does anyone think Surpass is infected?
__________________
www.msj3.comSPACERReseller - PASS83
SPACER
sneagle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 8:31 PM   #2 (permalink)
Dan
Staff of Surpass
Super #1
 
Dan's Avatar
 
Joined in Apr 2007
2,637 posts
Gave thanks: 137
Thanked 174 times
I've had my shots.. it aint me!
Dan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 8:53 PM   #3 (permalink)
﴾͡๏̯͡๏﴿...tweet
Super #1
 
Joined in Dec 2005
5,755 posts
Gave thanks: 145
Thanked 151 times
no... your network is infected.
__________________
poof
Brandonnn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 8:57 PM   #4 (permalink)
Surpass Fan
On a golden path...
 
sneagle's Avatar
 
Joined in Oct 2005
Lives in Northern NJ
Hosted on PASS83
332 posts
Gave thanks: 6
Thanked 16 times
I am amused.

Still, I need to solve this problem? Anyone?
__________________
www.msj3.comSPACERReseller - PASS83
SPACER
sneagle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 8:58 PM   #5 (permalink)
He shoots.. He scores!
Super #1
 
puckchaser's Avatar
 
Joined in Feb 2007
Lives in A room with no windows.
Hosted on SH110
1,424 posts
Gave thanks: 43
Thanked 137 times
Considering the virus is a W32 (ie WINDOWS based virus) and unless you have a dedicated server running Windows, your Surpass server running Linux cannot be infected with a W32 virus.

Case closed.
Next!
__________________
SH110
puckchaser is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 9:15 PM   #6 (permalink)
Surpass Fan
On a golden path...
 
sneagle's Avatar
 
Joined in Oct 2005
Lives in Northern NJ
Hosted on PASS83
332 posts
Gave thanks: 6
Thanked 16 times
Quote:
Originally Posted by puckchaser View Post
Considering the virus is a W32 (ie WINDOWS based virus) and unless you have a dedicated server running Windows, your Surpass server running Linux cannot be infected with a W32 virus.
I have a reseller.

I sorta figured what you said is the case. However, how do I convince the network people and more importantly the automated software blocking the site?
__________________
www.msj3.comSPACERReseller - PASS83
SPACER
sneagle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 9:39 PM   #7 (permalink)
He shoots.. He scores!
Super #1
 
puckchaser's Avatar
 
Joined in Feb 2007
Lives in A room with no windows.
Hosted on SH110
1,424 posts
Gave thanks: 43
Thanked 137 times
Tell them that your Surpass server runs Linux and can not be the cause of their virus. If your IT people can't figure that out, then you will most likely be out of luck because they are idiots.
__________________
SH110
puckchaser is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 9:46 PM   #8 (permalink)
Surpass Fan
On a golden path...
 
sneagle's Avatar
 
Joined in Oct 2005
Lives in Northern NJ
Hosted on PASS83
332 posts
Gave thanks: 6
Thanked 16 times
This is the original comment from the IT folks (I have not yet discussed with them that this is a Linus server.)

My guess is that the scanning process will not be able to tell a Windows server from an Linux server...
Quote:
It will not be possible to open access to your web site through the firewall. I had some confusion in why we were blocking your site at the firewall level. The reason for the confusion is that we don’t scan for content here. What we do scan for is protocol ( port addresses ) and your host is broadcasting the same port address that the Nirbot virus talks over. This means that this host is most likely infected with the same virus that infected us last February.

So, unfortunately, we will not be opening up this site.

It might be best to reach out to your host provider to see if they can update “patch” their servers with the latest MS security patches and AV patches…
__________________
www.msj3.comSPACERReseller - PASS83
SPACER
sneagle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old May 29th, 2007, 9:53 PM   #9 (permalink)
He shoots.. He scores!
Super #1
 
puckchaser's Avatar
 
Joined in Feb 2007
Lives in A room with no windows.
Hosted on SH110
1,424 posts
Gave thanks: 43
Thanked 137 times
Quote:
Originally Posted by sneagle View Post
This is the original comment from the IT folks (I have not yet discussed with them that this is a Linus server.)

My guess is that the scanning process will not be able to tell a Windows server from an Linux server...

I would explain that your server is running Linux. They are looking for MS (microsoft) patches. Find out what port seems to be the issue, and see if you can open ticket with Surpass.
__________________
SH110
puckchaser is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On