Re: kitty.avast.com scanning my ports and internal process trying to access their ip

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 05/03/04


Date: Sun, 02 May 2004 18:48:43 -0400

On Sun, 02 May 2004 14:17:58 +0200, Claudio spoketh

>On April 30 I visited the "avast" (antivirus) site looking for a free
>antivirus. I browsed for less than 5 minutes and downloaded nothing.
>
>On May 1st I read in my Kerio 4 firewall log:
>
>'01/May/2004 10:46 "port scan has been detected" remote address
>"kitty.avast.com" permitted'
>
>Since this rang an alarm bell, I set a rule in Kerio to block their
>IPs, then
>
>'01/May/2004 22:25:23 application <tcpip kernel driver> out remote
>addres "kitty.avast.com" protocol "ICMP" denied

Are there any more details in these logs? A port scan often indicates
something coming from the outside trying to get in, not the other way
around.

How about providing a bit more about these connections. Source and
destination would be nice, as well as port numbers (both source and
destination as well).

The ICMP you see is most likely an ICMP port unreachable or host
unreachable message, and it's because you are blocking that IP address
(or addresses). What caused the ICMP is still unclear, since we've seen
no log data from you ...

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)



Relevant Pages

  • Re: Problem sending E-mail to 1 server
    ... If I try the same thing (telnet to port ... Source IP: 64.208.166.12, Destination IP: 66.133.129.70 ... PROTOCOL: ICMP ... Header checksum: 0xEE82 ...
    (microsoft.public.exchange.admin)
  • Re: ipfw-ntad-jail
    ... > Ok, so I setup IPFW and NATd on my freeBSD 4.5-RELEASE box, ... > host (dagobah) ... > allow ftp (port 21) ... > add 00600 allow icmp from any to any icmptypes 3 ...
    (FreeBSD-Security)
  • RE: MAPI problem with HrGetServerDN
    ... 'Destination Host Unreachable ... Private Declare Function WSACleanup Lib "WSOCK32.DLL" As Long ... 'Create a handle on which Internet Control Message Protocol (ICMP) requests ... Private Declare Function inet_addr Lib "WSOCK32.DLL" (ByVal cp As String) As ...
    (microsoft.public.exchange.applications)
  • Re: Survive without ICMP?
    ... ICMP resides above IP protocol, ... it receives a UDP or TCP packet on port 0 would be packets ... ICMP Type 3 Code 3 (Port unreachable). ... when it receives a TCP packet to a forbidden port which may ...
    (comp.security.firewalls)
  • Re: Survive without ICMP?
    ... > an Orion modem, Linksys programmable router, three machines ... > Linksys router responding to port 0 requests. ... > a timestamp ICMP did make it through to our hack testing. ... > the ICMP packet for a netmask. ...
    (comp.security.firewalls)

Quantcast