Clueless newbie to firewalls (sygate) seeks info
From: FYIS.org/estore (DanlK_at_nospam.net)
Date: 04/28/05
- Next message: Jason Edwards: "Re: is Zone allam locking up?"
- Previous message: Jose Maria Lopez Hernandez: "Re: [Symantec] NNTP = TCP now?"
- Next in thread: Jason Edwards: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Reply: Jason Edwards: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Reply: Mike: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 28 Apr 2005 05:28:05 -0400
Seeking reference material (URL) that might help to explain incoming hits
like the one below.
What is all this stuff being sent to me?
Am using Sygate Personal Firewall (Win98SE) for the first time as a
broadband cable subscriber, and am getting numerous hits from an incoming
addresses with & without packet data, among them one example identified as
follows:
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 10.0.0.0 - 10.255.255.255
CIDR: 10.0.0.0/8
NetName: RESERVED-10
NetHandle: NET-10-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: BLACKHOLE-1.IANA.ORG
NameServer: BLACKHOLE-2.IANA.ORG
Comment: This block is reserved for special purposes.
Comment: Please see RFC 1918 for additional information.
Comment:
RegDate:
Updated: 2002-09-12
File Version : 4.10.0.2222
File Description : Win32 Kernel core component (kernel32.dll)
File Path : C:\WINDOWS\SYSTEM\kernel32.dll
Process ID : 0xFFCFD0F5 (Heximal) 4291809525 (Decimal)
Connection origin : remote initiated
Protocol : UDP
Local Address : 255.255.255.255
Local Port : 68 (BOOTPC - Dynamic Host Configuration Protocol [DHCP]
Client)
Remote Name :
Remote Address : 10.222.64.1
Remote Port : 67
Ethernet packet details:
Ethernet II (Packet Length: 384)
Destination: ff-ff-ff-ff-ff-ff
Source: 00-0b-fc-40-28-54
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.0.. = Don't fragment: Not set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 255
Protocol: 0x11 (UDP - User Datagram Protocol)
Header checksum: 0x1bb2 (Correct)
Source: 10.222.64.1
Destination: 255.255.255.255
User Datagram Protocol
Source port: 67
Destination port: 68
Length: 8
Checksum: 0x3542 (Correct)
Bootstrap Protocol
Boot Reply
Option 53: DHCP Message Type = DHCP Offer
Option 54: Server Identifier = 68.87.71.0
Option 51: IP Address Lease Time = 6 days, 16 hours
Option 1: Subnet Mask = 255.255.248.0
Option 66: Unknown Option (11 Bytes)
Option 3: Router = 10.222.64.0
Option 2: Unknown Option (4 Bytes)
Option 4: Unknown Option (4 Bytes)
Option 7: Unknown Option (4 Bytes)
Option 128: Unknown Option (4 Bytes)
Option 67: Unknown Option (19 Bytes)
Binary dump of the packet:
0000: FF FF FF FF FF FF 00 0B : FC 40 28 54 08 00 45 00 | .........@(T..E.
0010: 01 72 BD 80 00 00 FF 11 : B2 1B 0A DE 40 01 FF FF | .r..........@...
0020: FF FF 00 43 00 44 01 5E : 42 35 02 01 06 00 00 0E | ...C.D.^B5......
0030: 54 F2 00 00 80 00 00 00 : 00 00 0A DE 45 C3 44 57 | T...........E.DW
0040: 47 0D 0A DE 40 01 00 11 : 1A 59 1C 4C 00 00 00 00 | G...@....Y.L....
0050: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0060: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0070: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0080: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0090: 00 00 00 00 00 00 64 31 : 31 5F 77 61 6C 6C 65 64 | ......d11_walled
00A0: 67 61 72 64 65 6E 2E 63 : 6D 00 00 00 00 00 00 00 | garden.cm.......
00B0: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
00C0: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
00D0: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
00E0: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
00F0: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0100: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 00 | ................
0110: 00 00 00 00 00 00 63 82 : 53 63 35 01 02 36 04 44 | ......c.Sc5..6.D
0120: 57 47 0B 33 04 00 08 CE : DD 01 04 FF FF F8 00 42 | WG.3...........B
0130: 0B 36 38 2E 38 37 2E 37 : 31 2E 31 33 03 04 0A DE | .68.87.71.13....
0140: 40 01 02 04 FF FF C7 C0 : 04 04 44 57 47 0D 07 04 | @.........DWG...
0150: 00 00 00 00 80 04 00 00 : 00 00 43 13 64 31 31 5F | ..........C.d11_
0160: 77 61 6C 6C 65 64 67 61 : 72 64 65 6E 2E 63 6D 00 | walledgarden.cm.
0170: 00 00 00 00 00 00 00 00 : 00 00 00 00 00 00 00 FF | ................
TIA,
DanlK, FYI Services Collectibles
www.FYIS.org
- Next message: Jason Edwards: "Re: is Zone allam locking up?"
- Previous message: Jose Maria Lopez Hernandez: "Re: [Symantec] NNTP = TCP now?"
- Next in thread: Jason Edwards: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Reply: Jason Edwards: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Reply: Mike: "Re: Clueless newbie to firewalls (sygate) seeks info"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]