blackice reports localhost intrusions !?!?!

From: Mariano (mborghi_at_wcstechnology.com)
Date: 11/10/03


Date: 10 Nov 2003 07:03:56 -0800

before updating my blackice to the latest 3.6cbx version, blackice
start
reporting attacks from my own machine, on various different ports like
80, 2234, 2240 and some others.
some of the attacked ports reported are open, like 2234 and 2240 (i
use soulseek on those ports), but port 80 is closed, since i have
blackice set to PARANOID.
Everything was working fine for months, but now i get a lot of attacks
reported.
I know i can trust and accept events from an intruder, setting this
ON, eliminate the attacks report, but i have a DSL connection, so the
IP addres change once a day, so the solution is useless.
Anyway everything is working fine, i mean, intrusions on soulseek port
2234 port are reported, but it seems that do not not affect the
tranfers or correct program functionality.
If anybody have experienced this and have a solution or explanation i
will thank you to share it with me.
or maybe be is a blackice bug?

mariano



Relevant Pages

  • Re: [Full-disclosure] Brute force attack - need your advice
    ... But please state a config that someone with experience can not get into, is more of a point that security is ever evolving. ... Yup it is security by obscurity and it will help against a script kiddie that won't take the time to scan all ports, thats why I suggested move to a high non-standard port. ... I'm not talking about downloading blacklists but dynamic firewall rules and scripting to achieve a dynamic list based on ranking of attacks against the box. ...
    (Full-Disclosure)
  • System hanging in acpi during shutdown
    ... including acpi and it now hangs during shutdown after reporting: ... This is a Gigabyte GA-7VRXP motherboard and dmesg reports: ... pci0: <PCI bus> on pcib0 ... 2 ports with 2 removable, ...
    (freebsd-stable)
  • Re: Black Ice is bad stuff! BEWARE!
    ... BID's firewall to do many things to protect my home network. ... because I have read the Adv User Manual for BlackIce. ... IP* on those two ports. ... The protection of the machine is a process and is not a given! ...
    (comp.security.firewalls)
  • Re: Scanning Class A network
    ... >network to identify hosts and ports exposed to the Internet. ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • RE: Scanning Class A network
    ... The network you're scanning will have changed significantly in the time ... Assuming you could build a cluster to check 100,000 ports per second, ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
    (Pen-Test)