Re: kitty.avast.com scanning my ports and internal process trying to access their ip

From: Claudio (Delete_fa1_at_italtrade.net)
Date: 05/03/04

  • Next message: Claudio: "Re: kitty.avast.com scanning my ports and internal process trying to access their ip"
    Date: Mon, 03 May 2004 10:10:42 +0200
    
    

    On Sun, 02 May 2004 18:48:43 -0400, Lars M. Hansen
    <badnews@hansenonline.net> wrote:

    >Are there any more details in these logs? A port scan often indicates
    >something coming from the outside trying to get in, not the other way
    >around.
    >
    >How about providing a bit more about these connections. Source and
    >destination would be nice, as well as port numbers (both source and
    >destination as well).

    (from copy/paste action)

    >From Kerio's ids.log:

    [01/May/2004 10:20:46] "Ids" action = permitted, raddr = 66.98.166.72,
    msg = '"Port scan has been detected"', url = '', direc = in,
    class = 'network-scan', priority = portscan

    >From Kerio's network.log:

    [01/May/2004 22:25:23] "Network" action = 'denied', descr = 'Avast
    anti virus site', proto = 1, laddr = 192.168.0.184, raddr =
    66.98.166.72, direc = 'out', ruleId = 473153536, proc = '<Tcpip Kernel
    Driver>'

    [01/May/2004 22:25:29] "Network" action = 'denied', descr = 'Avast
    anti virus site', proto = 1, laddr = 192.168.0.184, raddr =
    66.98.166.72, direc = 'out', ruleId = 473153536, proc = '<Tcpip Kernel
    Driver>'

    Notes:

    - The 'Avast anti virus site' description is mine.
    After the morning portscan I wrote a rule blocking the 66.98.166.72 IP
    (and others) with that name.

    - proto = 1 means ICMP, this is how it is visualized the log in
    Kerio's graphical interface.

    - IP 66.98.166.72 is kitty.avast.com

    >The ICMP you see is most likely an ICMP port unreachable or host
    >unreachable message, and it's because you are blocking that IP address
    >(or addresses). What caused the ICMP is still unclear, since we've seen
    >no log data from you ...

    I am not sure of what you mean.
    However you do rise some doubts.

    I verified what you seem to imply: I tried to reach www.avast.com
    with Opera while the firewal is set to block the IP (I blocked ALL
    their IPs, about 5 or 6).
    The log shows:

    [03/May/2004 09:48:07] "Network" action = 'denied', descr = 'Avast
    anti virus site', proto = 6, laddr = 0.0.0.0, raddr = 216.12.202.5,
    lport = 3049, rport = 80, direc = 'out', ruleId = 204652544, proc =
    'C:\PROGRAMMI\INTERNET\OPERA\OPERA.EXE'

    a) the protocol is TCP not ICMP
    b) the local address is 0.0.0.0 instead of 192.168.0.184
    c) the process is Opera not <Tcpip Kernel Driver>
    d) the remote IP is 216.12.202.5
    [based on my logs, www.avast.com was resolved as 66.98.166.72
    (kitty.avast.com) on Sunday and as 216.12.202.5 (lynx.avast.com) on
    monday].

    In other words, the situation with ICMP packets going out is not
    reproduced.

    Was that what you meant ?


  • Next message: Claudio: "Re: kitty.avast.com scanning my ports and internal process trying to access their ip"

    Relevant Pages

    • RE: MAPI problem with HrGetServerDN
      ... 'Destination Host Unreachable ... Private Declare Function WSACleanup Lib "WSOCK32.DLL" As Long ... 'Create a handle on which Internet Control Message Protocol (ICMP) requests ... Private Declare Function inet_addr Lib "WSOCK32.DLL" (ByVal cp As String) As ...
      (microsoft.public.exchange.applications)
    • Re: Strange MTU Problem
      ... Does the router know how to forward the ICMP ... On the local side, a packet has real source address and destination, ...
      (comp.os.linux.networking)
    • Re: Possible ICMP DOS spoofed to Nameservers?
      ... Which is Destination Unreachable, Communication Administratively ... That may be because an intermeidate device is the one sending the ICMP ... packets, i.e. a router in front of the address you are sending packets to. ...
      (Incidents)
    • Re: Removing ping/icmp from a network
      ... (the receiver should get a hint of this when his SYN's don't get a SYN ... Destination unreachable messages do quite a bit more than "notify the ... ICMP is the least of your problems. ... "All vulnerabilities deserve a public fear period prior to patches ...
      (Security-Basics)
    • RE: Removing ping/icmp from a network
      ... The simple answer is to limit ICMP. ... It is not needed by all hosts to all hosts. ... (the receiver should get a hint of this when his SYN's don't get a SYN ... Destination unreachable messages do quite a bit more than "notify the ...
      (Security-Basics)