New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Strange outgoing connections on netvm #3184

Closed
guudeve opened this Issue Oct 18, 2017 · 3 comments

Comments

Projects
None yet
3 participants
@guudeve

guudeve commented Oct 18, 2017

Qubes version: 3.2(R3.2)
Netvm-Template: Fedora 25

I'm seeing some weird outgoing connections on my netvm. My machines IP is 192.168.33.2. Why would there be netbios connections going to a public IP 198.105.254.24. Is the below normal?

05:36:03.443684 IP (tos 0x0, ttl 64, id 6438, offset 0, flags [DF], proto UDP (17), length 78)
192.168.33.2.49488 > 192.168.33.31.137: [udp sum ok]

NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x4DB3
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=SAMBA NameType=0x1B (Domain Controller)
QuestionType=0x20
QuestionClass=0x1
05:36:04.445704 IP (tos 0x0, ttl 64, id 27215, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.2.37978 > 192.168.33.1.53: [udp sum ok] 4837+ A? SAMBA. (23)
05:36:04.445759 IP (tos 0x0, ttl 64, id 27216, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.2.37978 > 192.168.33.1.53: [udp sum ok] 53022+ AAAA? SAMBA. (23)
05:36:04.485630 IP (tos 0x0, ttl 64, id 55500, offset 0, flags [DF], proto UDP (17), length 83)
192.168.33.1.53 > 192.168.33.2.37978: [udp sum ok] 4837 q: A? SAMBA. 2/0/0 SAMBA. A 198.105.254.24, SAMBA. A 198.105.244.24 (55)
05:36:04.490176 IP (tos 0x0, ttl 64, id 55501, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.1.53 > 192.168.33.2.37978: [udp sum ok] 53022 q: AAAA? SAMBA. 0/0/0 (23)
05:36:04.490944 IP (tos 0x0, ttl 64, id 27221, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.2.57979 > 192.168.33.1.53: [udp sum ok] 35831+ A? SAMBA. (23)
05:36:04.491013 IP (tos 0x0, ttl 64, id 27222, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.2.57979 > 192.168.33.1.53: [udp sum ok] 24542+ AAAA? SAMBA. (23)
05:36:04.493608 IP (tos 0x0, ttl 64, id 55502, offset 0, flags [DF], proto UDP (17), length 83)
192.168.33.1.53 > 192.168.33.2.57979: [udp sum ok] 35831 q: A? SAMBA. 2/0/0 SAMBA. A 198.105.244.24, SAMBA. A 198.105.254.24 (55)
05:36:04.512080 IP (tos 0x0, ttl 64, id 55503, offset 0, flags [DF], proto UDP (17), length 51)
192.168.33.1.53 > 192.168.33.2.57979: [udp sum ok] 24542 q: AAAA? SAMBA. 0/0/0 (23)
05:36:04.512609 IP (tos 0x0, ttl 64, id 23963, offset 0, flags [DF], proto TCP (6), length 52)
192.168.33.2.39248 > 198.105.244.24.139: Flags [S], cksum 0x88c5 (correct), seq 4200154075, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 5], length 0
05:36:04.522988 IP (tos 0x0, ttl 64, id 37282, offset 0, flags [DF], proto TCP (6), length 52)
192.168.33.2.56624 > 198.105.254.24.139: Flags [S], cksum 0x00cc (correct), seq 3898904553, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 5], length 0
(END)

@tonsilware

This comment has been minimized.

Show comment
Hide comment
@tonsilware

tonsilware Oct 18, 2017

https://whois.arin.net/rest/nets;q=198.105.254.24?showDetails=true&showARIN=false&showNonArinTopLevelNet=false&ext=netref2

It might be possible that your ISP has "sold" your DNS traffic to Search Guide Inc and Search Guide Inc are hijacking all your unresolvable DNS queries in order to show you adverts. Which DNS servers are you using?

Solution might be to manually set your router / computers to use another DNS service, e.g. Google's DNS servers (8.8.8.8 and 8.8.4.4) or OpenDNS (208.67.222.222 and 208.67.220.220).

tonsilware commented Oct 18, 2017

https://whois.arin.net/rest/nets;q=198.105.254.24?showDetails=true&showARIN=false&showNonArinTopLevelNet=false&ext=netref2

It might be possible that your ISP has "sold" your DNS traffic to Search Guide Inc and Search Guide Inc are hijacking all your unresolvable DNS queries in order to show you adverts. Which DNS servers are you using?

Solution might be to manually set your router / computers to use another DNS service, e.g. Google's DNS servers (8.8.8.8 and 8.8.4.4) or OpenDNS (208.67.222.222 and 208.67.220.220).

@guudeve

This comment has been minimized.

Show comment
Hide comment
@guudeve

guudeve Oct 18, 2017

Hey tonsilware you are absolutely right. This is so creepy! what the hell is wrong with Charter? they scared the crap out of me. I found this virus total link https://www.virustotal.com/en-gb/ip-address/198.105.254.24/information/ | https://www.virustotal.com/en-gb/ip-address/198.105.244.24/information/ and a reddit report about them doing hijacking as well https://www.reddit.com/r/AskNetsec/comments/3gcz7m/charter_injecting_scripts_into_my_browser/. I do use their dns server. I'm gonna change it to Google. I wish i could setup a vpn on my router but i use Netflix and other streaming services that do not allow vpn. Thanks!

guudeve commented Oct 18, 2017

Hey tonsilware you are absolutely right. This is so creepy! what the hell is wrong with Charter? they scared the crap out of me. I found this virus total link https://www.virustotal.com/en-gb/ip-address/198.105.254.24/information/ | https://www.virustotal.com/en-gb/ip-address/198.105.244.24/information/ and a reddit report about them doing hijacking as well https://www.reddit.com/r/AskNetsec/comments/3gcz7m/charter_injecting_scripts_into_my_browser/. I do use their dns server. I'm gonna change it to Google. I wish i could setup a vpn on my router but i use Netflix and other streaming services that do not allow vpn. Thanks!

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 19, 2017

Member

Closing this as "resolved." If you believe the issue is not yet resolved, or if anyone is still affected by this issue, please leave a comment, and we'll be happy to reopen this. Thank you.

Member

andrewdavidwong commented Oct 19, 2017

Closing this as "resolved." If you believe the issue is not yet resolved, or if anyone is still affected by this issue, please leave a comment, and we'll be happy to reopen this. Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment