Re: ICMP - What the hell are these log files telling me.....

From: Maxime Ducharme (maxime_at_pandore-designSPAMISBAD.com)
Date: 10/31/03


Date: Fri, 31 Oct 2003 09:22:13 -0500


"Gary Brett" <globalg2001@yahoo.co.uk> wrote in message
news:5b221b4d.0310310202.2704973e@posting.google.com...
> Thanx for the response.

you're welcome

> Will check the sugggestion out. Is it a good idea to turn off logging
> of ICMP on the SonicWALL, to reduce the log files do you think?
>

it is a good idea to limit 'em in case you're flooded with ICMP ping,
it could result in a disk full problem

> Also after I wrote the original message I discovered I had a "Sockets
> De Trois V1" trojan on all my LAN XP Pro machines.

thats bad

> I have since closed
> port 5000 on the Firewall and have disabled "SSDP Discovery Service"
> in WinXP Services.

it is good you closed the service if you dont need

i also suggest you close every ports on your firewall and only let the
one you need

> This seems to have stopped the Trojan, but do you
> know how it entered the LAN and what it actaully does when inside.

this is usually harder to find, the best way to start it to google
the most info you can

>
> Again thanx for your time..
>
> Gary

np :)

 ---------------------------------------------------------------
   Maxime Ducharme
   Administrateur reseau, Programmeur



Relevant Pages

  • Re: Strange ICMP packets
    ... >a remote IP and not a LAN IP and nothing on the machine is initiating it. ... the rules on the firewall are set to block all ICMP. ... because ICMP errors must not cause an ICMP ... While ICMP packets _could_ be longer, ...
    (comp.security.firewalls)
  • Re: Unblock ICMP on Windows Server 2003 SP1
    ... All my servers are on SP1 and there are ... no ICMP issues across the VPN nor have I ever read of any. ... a client from LAN A cannot ping another client ... > in LAN B, however they are still able to access resources on both LANs. ...
    (microsoft.public.win2000.ras_routing)
  • RE: Cant ping VPN clients from LAN
    ... In default ICMP is not allowed. ... resources on the LAN just fine, but while they are connected, I can't ... ping them from the LAN. ...
    (microsoft.public.win2000.ras_routing)