Re: Ports getting hammered?
- From: "Duane Arnold" <No@xxxxxx>
- Date: Tue, 03 Jan 2006 14:47:41 GMT
"Somebody." <somebody.@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:kzvuf.8299$43.4307@xxxxxxxxxxxxxxx!nnrp1.uunet.ca...
>
> "SHRED" <noone@xxxxxxxxxxx> wrote in message
> news:7Aduf.6614$JT.1576@xxxxxxxxxxxxx
>> Duane Arnold wrote:
>>> "SHRED" <noone@xxxxxxxxxxx> wrote in message
>>> news:baduf.6609$JT.1968@xxxxxxxxxxxxx
>>>
>>>>Duane Arnold wrote:
>>>>
>>>>>"SHRED" <noone@xxxxxxxxxxx> wrote in message
>>>>>news:vLcuf.6541$JT.5496@xxxxxxxxxxxxx
>>>>>
>>>>>
>>>>>>I no very little about firewalls.
>>>>>>My setup:
>>>>>>
>>>>>>Cable access
>>>>>>4 port SMC Barricade Router
>>>>>>2 computers
>>>>>>
>>>>>>
>>>>>>I recently installed ZoneAlarm and it is blocking attempts at port
>>>>>>access.
>
>
>> 7664703 Packet DROPPED: Proto: IP_UDP Flags: 0x0000000a Src:
>> 218.19.119.233 Dest: 192.168.123.143 SrcPort: 23421 DstPort: 1689
>>
>
> Something on your machine is attempting to connect out over the port most
> commonly used for IMAP, a mail protocol.
>
> Probably some spyware calling home.
>
> Your ZA is blocking it, but it's there, and operating.
>
> It may be successfully connecting out on other ports.
>
> Your SMC is likely not configured to block any outbound connections.
>
> -Russ.
How is that possible? The log clearly indicates unsolicited inbound packets
are being dropped. Please explain to me how any PFW or any FW solution knows
that dubious outbound traffic is be sent from a machine and the it's going
to make some decision to start blocking outbound, because something is
phoning home? If the malware running on the machine solicited the traffic
from the remote IP, the PFW is not stopping anything.
Duane :)
.
- Follow-Ups:
- Re: Ports getting hammered?
- From: Somebody.
- Re: Ports getting hammered?
- References:
- Ports getting hammered?
- From: SHRED
- Re: Ports getting hammered?
- From: Duane Arnold
- Re: Ports getting hammered?
- From: SHRED
- Re: Ports getting hammered?
- From: Duane Arnold
- Re: Ports getting hammered?
- From: SHRED
- Re: Ports getting hammered?
- From: Somebody.
- Ports getting hammered?
- Prev by Date: Re: ZoneAlarm shuts down my DSL connection
- Next by Date: Re: FYI ZoneAlarm ZoneAlarm Pro 6.0.31.003 Problems on an XP Home cpr
- Previous by thread: Re: Ports getting hammered?
- Next by thread: Re: Ports getting hammered?
- Index(es):
Relevant Pages
|