Re: linksys wrt54g router seems to leak.



CJWertz@xxxxxxxxx writes:
This can probably be considered a newbie kind of question.

I have a linksys wrt54g broadband router (firmware version 3.03.6).
Right ow, I have wireless disabled because I don't need it.

Good.


I have firewall protection enabled. My knowledge about this is
limited, but my impression is that enabling the firewall prevents
unsolicited internet traffic from getting past the router into my home
network.

It's supposed to, yes.

I also have McAFee Personal Firewall Plus (v 7.1) running on this
PC. The firewall log tells me that McAFee is blocking occasional
connection attempts.

----------------------------------------------------------------------
Here are a some recent samples:

-- A computer at ichart1.finance.vip.re4.yahoo.com has attempted an
unsolicited connection to TCP port 1862 on your computer.
TCP port 1862 is commonly used by the "techra-server" service or
program.

Were you looking at yahoo finance at the time?

-- A computer at bs1b1.ads.vip.re2.yahoo.com has attempted an
unsolicited connection to TCP port 1859 on your computer.

--A computer at dl00053.lunarpages.com has attempted an unsolicited
connection to TCP port 1790 on your computer.
TCP port 1790 is commonly used by the "Narrative Media Streaming
Protocol" service or program.

--A computer at IP Address 64.95.25.214 has attempted an unsolicited
connection to TCP port 2925 on your computer.
TCP port 2925 is commonly used by the "Firewall Redundancy Protocol"
service or program.
------------------------------------------

Some of these appear benign enough; I can't figure some of them out.

My question is how and why do they get through the hardware firewall?

I've tried to research this, but have yet to find the right place to
look.

This doesn't look terribly good. :-\

For comparison, in my software firewall log, I see nothing but source
IP's from my LAN, localhost, and hosts on the network to which I VPN
(via software vpn client on my pc).

Turn your router over. What hardware version is it? v1/2/3/4/5?

Now, some older ones IIRC were simple packet filters where pushing
some packets past them was relatively easy--doing something useful
with them was harder though, complicated by the NAT issue. Later
models implemented stateful packet inspection which improved things
further. Now, are you using the default IP address range or did you
reassign it? Has your router been hacked-- if you login to its admin
interface, have hosts on your lan perhaps been added to the DMZ (hence
sitting right on the 'net)? There are vulnerabilities on those wrt54g
boxes out there and if you've never updated the firmware, you might
have been hit by the script kiddies. Cross site scripting attacks are
also possible agains the admin login interface, bypassing any security
and allowing router access.



Best Regards,
--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: what about when....
    ... working, then try the Web connection, if you absolutely need that ability. ... Don't test by sitting at a second machine behind the router and putting ... If you know RD is active on the host machine, have forwarded the port in the ... Possible issues are some other firewall mechanism--software on the host ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: [SLE] ADSL Broadband advice please
    ... > I now meet all criteria and am about to sign up for an adsl connection ... > support the Dlink DSL-504 router, but there is a cost to consider. ... > Both these leave the firewall at the software level on the SuSE box I ...
    (SuSE)
  • Re: OT udp port 138 BROWSER traffic
    ... >>potential problems with people outside the firewall looking at disk info ... > point of changing dsl providers. ... > issues that are interfering with my connection at their end. ... > firewall/router and their gateway, ...
    (comp.os.linux.security)
  • Re: If I suddenly disappear...
    ... >> Netgear router) connected to t'interwebby thingy pretty much 18 hrs per ... >> firewall is the NAT firewall on the router, ... That's in three years of fatpipe connection. ... some netty stuff that Mac OS 9 doesn't easily support (torrent d/ls ...
    (uk.rec.sheds)
  • Re: linksys wrt54g router seems to leak.
    ... unsolicited connection to TCP port 1862 on your computer. ... Has your router been hacked-- if you login to its admin ... The doc says this router does the stateful packet inspection. ...
    (comp.security.firewalls)