MP C6503 - attack source seen in MCAFEE LOGS

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rsyarcia
    Hair Straightener Tech

    500+ Posts
    • Feb 2008
    • 711

    #1

    MP C6503 - attack source seen in MCAFEE LOGS

    image010.jpg

    Guys,

    Need your help regarding this issue, customer is complaining that our machine has virus based on the logs. Deactivated SMB protocol in the machine but still the same. Is this an issue from the MFP or on their network? thanks for your support.
    Nobody is perfect..
  • habik
    Service Manager

    Site Contributor
    1,000+ Posts
    • Apr 2010
    • 2013

    #2
    Re: MP C6503 - attack source seen in MCAFEE LOGS

    Have you added it in McAffee as friendly network device?


    Sent from my iDon't believe in marketing device using Tapatalk
    .OK Google! ... will I need Berrocca this morning?
    Firmwares HERE

    Comment

    • rthonpm
      Field Supervisor

      2,500+ Posts
      • Aug 2007
      • 2847

      #3
      Re: MP C6503 - attack source seen in MCAFEE LOGS

      There is no known virus to affect the NetBSD kernel of this MFP. McAfee is well known for false positives in its scanning: it sees something that 'kind of looks like' a denial of service attack so the heuristics decide it is one. More than likely the device hasn't been set in the McAfee console as a valid network device.

      Has the customer's IT also looked to see if the MFP is also looking for a master browser for the network, or if it's trying to announce itself as such for the purposes of SMB naming? Are the DNS settings correct?

      I've complained before about the sad state of customer IT, but just going off one log without doing the requisite investigation to see if other events on the network give some idea of what might be going on is just getting ridiculous.

      Sent from my Classic using Tapatalk

      Comment

      • KenB
        Geek Extraordinaire

        2,500+ Posts
        • Dec 2007
        • 3944

        #4
        Re: MP C6503 - attack source seen in MCAFEE LOGS

        Since our machines are basically a "black box" to most IT people, I guess it's only logical that they get tagged as virus spreaders.

        Must be the natural fear of the unknown, I guess.
        “I think you should treat good friends like a fine wine. That’s why I keep mine locked up in the basement.” - Tim Hawkins

        Comment

        • rsyarcia
          Hair Straightener Tech

          500+ Posts
          • Feb 2008
          • 711

          #5
          Re: MP C6503 - attack source seen in MCAFEE LOGS

          Thanks for your replies, we'll visit the customer next week, update you once done.
          Nobody is perfect..

          Comment

          • qbert69
            Service Manager

            1,000+ Posts
            • Mar 2013
            • 1152

            #6
            Re: MP C6503 - attack source seen in MCAFEE LOGS

            Maybe turn off SNMP....and/or turn off Bonjour???...these "ping" protocols have been known to "flood" the network with extraneous traffic!!!

            REACH FOR THE STARS!!!
            Konica Minolta Planetariums!
            https://www.konicaminolta.com/planet...gma/index.html

            Comment

            Working...