Re: On connecting to the Internet

From: Mark Sykes (realnews_at_network.org)
Date: 10/08/03


Date: Thu, 09 Oct 2003 04:30:29 +1000

On Wed, 08 Oct 2003 13:41:49 GMT, "David" <davidwnh@adelphia.net>
wrote:

>Its all laid out in RFC 1256 for the router discovery protocol.
>Here's a good link with a short explanation for the layman:
>http://www.networkcomputing.com/netdesign/1107icmp7.html?ls=NCJS_1107bt
>
>If you have the proper gateway address entered into the dial up connection's
>configuration you can probably filter these packet's with no adverse
>affects.
>
>Multicasting is not just for client applications to send IM or video
>streams, etc to groups. It is simply an addressing scheme that is more
>efficient than using unicast or broadcast addresses for certain things. So
>in your example when the OS is looking to update it's routing
>table(generally when you first initialize a network connection or if a
>router in your table doesn't seem to be responding) instead of using a
>broadcast address to look for local routers, it uses an address that
>specifically pertains to "all routers on the local subnet".
>
>So the real time networking role is simply that your machine has to know
>which router to use to send traffic whose destination is outside of the
>local subnet.
>> OK. What real-time networking role would cause a stand-alone dialup
>> box to need to do this query?
>>
>> Like, the only protocol used here is tcp. No ipx/spx, no netbios, no
>> netware and none of the rest.
>> Has it got anything to do with messaging or uploading ?
>>
>> regards

Thank you. That makes it clearer. So, it is reasonable to say that all
operating systems with an internet capability would perform the same
song and dance on connecting, is it not ?

Any windows user, or rather users of earlier versions of windows would
not be concerned or curious about these 'background transactions'
as they would be invisible, particularly if they run without a
firewall.

I wonder what other processes might be taking place 'behind the
scenes'. Take this for example ..

----------------------------------------------------------------------------------------------------------
I writing application in kernel mode (driver) - WIndows XP
I want my (trojan or backdoor) was invisible
socket-------tcpip----+------firewalll-------+----ndis
                                  | 1.) |
2.)
                                 +-------my driver ----+
1. Hook it
2. Read address from ndis.sys from hard disk

What you think about my idea?
--------------------------------------------------------------------------------------------------------

Its a worry ! Trusted computing or misplaced trust.

regards



Relevant Pages

  • Re: Windows automatic updates
    ... > Richard....it is not a pre-requisite for a Windows user that in the long ... > situations which the Windows development team had failed to protect in the ... >> updates from now on. ... >> Regards, ...
    (microsoft.public.windowsxp.general)
  • Re: MessageId=6702 Severity=Error SymbolicName=DNS_EVENT_UPDATE_DS_PEERS_FAILURE
    ... it's a bit unusual for one of your NIC's to be in default windows 'I can't ... What's the IP ady of the router please? ... > connection spacific dns suffix: ... >> Regards, ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: How to Identify a culprit machine
    ... packet sniffer or managed switch and or router ... I have 2 windows 2000 networks sites connected by a 512kbps link. ... Best regards, ...
    (microsoft.public.windows.server.networking)
  • Re: BIG PROBLEM - with firewalls sudden reboot
    ... I notice that if I disabled my software firewall Norton 2002 ... with them losing their net connection and restarting windows.. ... A google shows that the router you mentioned is a USB or Ethernet ... do a win xp reinstall or a win xp repair. ...
    (comp.security.firewalls)
  • Re: pygame and python 2.5
    ... I realize you're a Windows user, and a Windows user with an AOL email ... developing a math library based on GMPY to use ... No, as I said elsewhere, I'm not a software developer, ...
    (comp.lang.python)