Monday, January 09, 2012

McAfee Relay Server 5.2.3 (Port 6515)

Earlier today I noticed I was getting a lot of TCP port 6515 proxies on The List.

Curious, I checked one and it gave me a VIA header of

1.1 Fran-PC (McAfee Relay Server 5.2.3)


Then I took a peek at the database.  Nearly 1900 of these things since December 1st, 2011.  Although the name of the PC above is a dead giveaway that this is some sort of consumer product ("[name-of-owner]-PC" is the default Windows machine name created during setup), a quick check of the DNS names of these boxes confirms they are all on residential IP addresses.

So what is "McAfee Relay Server"?  I'm guessing it's one of those snarky products they stick you with whenever you buy a new PC.  This makes sense, since December is a big month for new PCs.

But why install it as an open proxy?  

If it's a "security product" I hope it's a honeypot.

UPDATE: BIG LIST OF MCAFEE VIA HEADERS


This is what I have been able to salvage from the proxy run logs that I still have.  All of December is basically lost, unfortunately.

1.1 62G3CP1 (McAfee Relay Server 5.2.1)
1.1 acer-86e9bf2e61 (McAfee Relay Server 5.2.3)
1.1 Alan (McAfee Relay Server 5.2.3)
1.1 BERCOBACKUP (McAfee Relay Server 5.2.1)
1.1 bill-2eb924946b (McAfee Relay Server 5.2.3)
1.1 billkayredsa-PC (McAfee Relay Server 5.2.3)
1.1 blackkbarbie-PC (McAfee Relay Server 5.2.1)
1.1 bobot (McAfee Relay Server 5.2.3)
1.1 Breaker (McAfee Relay Server 5.2.3)
1.1 Brian-PC (McAfee Relay Server 5.2.0)
1.1 Buzz-PC (McAfee Relay Server 5.2.3)
1.1 CJ-PC (McAfee Relay Server 5.2.3)
1.1 ConwayVault (McAfee Relay Server 5.2.0)
1.1 Custom-PC (McAfee Relay Server 5.2.3)
1.1 D3Y34L91 (McAfee Relay Server 5.2.3)
1.1 D3ZQQW81 (McAfee Relay Server 5.2.3)
1.1 Daddy-PC (McAfee Relay Server 5.2.3)
1.1 Dan-PC (McAfee Relay Server 5.2.3)
1.1 Darla-PC (McAfee Relay Server 5.2.3)
1.1 david-PC (McAfee Relay Server 5.2.0)
1.1 DDS7CS81 (McAfee Relay Server 5.2.3)
1.1 Debby-PC (McAfee Relay Server 5.2.3)
1.1 dell (McAfee Relay Server 5.2.3)
1.1 denise-4f98da88 (McAfee Relay Server 5.2.3)
1.1 DG690771 (McAfee Relay Server 5.2.3)
1.1 DHWATSON (McAfee Relay Server 5.2.3)
1.1 dianadozard-PC (McAfee Relay Server 5.2.1)
1.1 DillonComput-PC (McAfee Relay Server 5.2.3)
1.1 donald-gpmxmpyb (McAfee Relay Server 5.2.3)
1.1 DSVR002557 (McAfee Relay Server 5.2.1)
1.1 DSVR006181 (McAfee Relay Server 5.2.3)
1.1 DSVR008084 (McAfee Relay Server 5.2.3)
1.1 eisberg (McAfee Relay Server 5.2.3)
1.1 eleni-PC (McAfee Relay Server 5.2.3)
1.1 emachine-98e05c (McAfee Relay Server 5.2.3)
1.1 Emachine (McAfee Relay Server 5.2.3)
1.1 FINISHIN-P6868U (McAfee Relay Server 5.2.3)
1.1 Fran-PC (McAfee Relay Server 5.2.3)
1.1 FTP-Server (McAfee Relay Server 5.2.3)
1.1 funk-sbs-2003 (McAfee Relay Server 5.2.3)
1.1 gary-393c91b143 (McAfee Relay Server 5.2.3)
1.1 general (McAfee Relay Server 5.2.3)
1.1 h1951093 (McAfee Relay Server 5.2.3)
1.1 hill-PC (McAfee Relay Server 5.2.3)
1.1 home (McAfee Relay Server 5.2.3)
1.1 Home-PC (McAfee Relay Server 5.2.3)
1.1 ILEXSA001 (McAfee Relay Server 5.2.3)
1.1 IQ-K12-Desktop (McAfee Relay Server 5.2.2)
1.1 IQ-K12-Desktop (McAfee Relay Server 5.2.3)
1.1 IQ-K12-Laptop (McAfee Relay Server 5.2.3)
1.1 Irvines-PC (McAfee Relay Server 5.2.3)
1.1 JackRogers-PC (McAfee Relay Server 5.2.3)
1.1 Jennifer-PC (McAfee Relay Server 5.2.3)
1.1 jennings-PC (McAfee Relay Server 5.2.3)
1.1 JERRY-PC (McAfee Relay Server 5.2.3)
1.1 Joanne (McAfee Relay Server 5.2.3)
1.1 Jody-PC (McAfee Relay Server 5.2.3)
1.1 JohnandCathy-PC (McAfee Relay Server 5.2.1)
1.1 john-HP (McAfee Relay Server 5.2.3)
1.1 JR-PC (McAfee Relay Server 5.2.3)
1.1 JTSICOE (McAfee Relay Server 5.2.3)
1.1 jupiter (McAfee Relay Server 5.2.3)
1.1 Kaminski-PC (McAfee Relay Server 5.2.1)
1.1 kedwards-PC (McAfee Relay Server 5.2.3)
1.1 keebaby5-PC (McAfee Relay Server 5.2.3)
1.1 Kit-PC (McAfee Relay Server 5.2.3)
1.1 LANG (McAfee Relay Server 5.2.3)
1.1 LarCar1969-PC (McAfee Relay Server 5.2.3)
1.1 manuel (McAfee Relay Server 5.2.3)
1.1 Mary-PC (McAfee Relay Server 5.2.3)
1.1 mdshor-PC (McAfee Relay Server 5.2.1)
1.1 millers-PC (McAfee Relay Server 5.2.1)
1.1 nanakatewest-PC (McAfee Relay Server 5.2.3)
1.1 nault-pc (McAfee Relay Server 5.2.3)
1.1 nichowa1-PC (McAfee Relay Server 5.2.3)
1.1 office (McAfee Relay Server 5.2.3)
1.1 owner-8477f6334 (McAfee Relay Server 5.2.3)
1.1 owner (McAfee Relay Server 5.2.3)
1.1 owner-PC (McAfee Relay Server 5.2.3)
1.1 Owner-PC (McAfee Relay Server 5.2.3)
1.1 pathenri-PC (McAfee Relay Server 5.2.3)
1.1 PCGARANT04 (McAfee Relay Server 5.2.2)
1.1 PRINCIPAL (McAfee Relay Server 5.2.3)
1.1 PServer (McAfee Relay Server 5.2.3)
1.1 PTBrunnock-PC (McAfee Relay Server 5.2.3)
1.1 Ratuld (McAfee Relay Server 5.2.3)
1.1 ricky-PC (McAfee Relay Server 5.2.3)
1.1 sarahcasey- (McAfee Relay Server 5.2.3)
1.1 server01 (McAfee Relay Server 5.2.3)
1.1 server_02 (McAfee Relay Server 5.2.3)
1.1 server152 (McAfee Relay Server 5.2.3)
1.1 Sharon-PC (McAfee Relay Server 5.2.3)
1.1 Shop-HP (McAfee Relay Server 5.2.3)
1.1 shulapc (McAfee Relay Server 5.2.3)
1.1 snowwhimpy-PC (McAfee Relay Server 5.2.3)
1.1 SRV-CAPYLR (McAfee Relay Server 5.2.3)
1.1 stanknight2-PC (McAfee Relay Server 5.2.3)
1.1 Sue (McAfee Relay Server 5.2.3)
1.1 Terry-PC (McAfee Relay Server 5.2.3)
1.1 Tommy-PC (McAfee Relay Server 5.2.3)
1.1 UBSPAULISTANO (McAfee Relay Server 5.2.1)
1.1 u-Net-NAS1 (McAfee Relay Server 5.2.1)
1.1 user-9y1zyxu5xh (McAfee Relay Server 5.2.3)
1.1 user (McAfee Relay Server 5.2.3)
1.1 User-PC (McAfee Relay Server 5.2.3)
1.1 virtualserver (McAfee Relay Server 5.2.3)
1.1 your-4dacd0ea75 (McAfee Relay Server 5.2.1)

There are some obvious corporate type names, but the -PC names are definitely consumer grade.  Again, the majority of all IPs reverse map back to residential address ranges.


Monday, January 02, 2012

Disappearing APs...


Related?


I wouldn't characterize the issue I've been seeing here as the access point "crashing" because it's still controllable after the ESSID disappears from the airwaves.

And of course I don't have a Dlink AP.

If I did I probably give it an ESSID of "Hlinky".  :o)


If you didn't know it already, Harald is not just some random guy on the Internet (like me).  If he says someone is crashing his APs, someone is crashing his APs.