Announcement

Collapse
No announcement yet.

A Firewall Question

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • A Firewall Question

    Does this makes sense? Looks mighty suspicious to me.



    "Beware of he who would deny you access to information, for in his heart he dreams himself your master" - Commissioner Pravin Lal.

  • #2
    Type the "remote host" values into your browser and see where they take you. Most likely something you have installed is trying to update itself.

    Comment


    • #3
      BTW., if ntoskrnl.exe appears in your process list when you press alt+ctrl+del it could be that you have a virus.

      Comment


      • #4
        I randomly checked a few of the remote hosts and they all lead to an identical page titles "Apache 2 Test Page
        powered by CentOS"

        ntoskrnl.exe does not appear in the process list though.

        Another strange thing that I noticed, is that the firewall sometimes tells me that my Firefox has changed, even when I haven't updated any new extensions.
        "Beware of he who would deny you access to information, for in his heart he dreams himself your master" - Commissioner Pravin Lal.

        Comment


        • #5
          Why is ntoskrnl.exe appearing in Sygate's list then?

          The firewall's tools should be enough for you to discover:

          1) what programs are sending or recieving data
          2) where they are sending or recieving from

          I don't use Sygate so I can't tell you exactly where to look.

          Comment


          • #6
            Another question, is why programs have lots of line?
            "Beware of he who would deny you access to information, for in his heart he dreams himself your master" - Commissioner Pravin Lal.

            Comment


            • #7
              Line? You mean more than one item in the list? That would be because one program can open as many connections as it wants, and the fiirewall is displaying all connections.

              Svchost.exe is different though, as it's not a program but a host for services. All sorts of programs can be services, so svchost.exe doesn't tell you much about what is happening.

              Comment


              • #8
                Go to Log Viewer, Security Log.
                Click on a line and run Back Trace Whois.
                Life is not measured by the number of breaths you take, but by the moments that take your breath away.
                "Hating America is something best left to Mobius. He is an expert Yank hater.
                He also hates Texans and Australians, he does diversify." ~ Braindead

                Comment


                • #9
                  Security Log is empty.

                  Whois on stuff in the Traffic Log provides:
                  inetnum: 81.35.0.0 - 81.39.255.255
                  netname: RIMA
                  descr: TELEFONICA DE ESPANA
                  descr: Provider Local Registry
                  country: ES
                  admin-c: ATDE1-RIPE
                  tech-c: TTDE1-RIPE
                  status: ASSIGNED PA
                  mnt-by: MAINT-TdE
                  mnt-lower: MAINT-TdE
                  mnt-routes: MAINT-TdE
                  source: RIPE # Filtered

                  role: Administradores Telefonica de Espana
                  address: Ronda de la Comunicaciףn s/n
                  address: Edificio Norte 1, planta 6x
                  address: 28050 Madrid
                  address: SPAIN
                  org: ORG-TDE1-RIPE
                  admin-c: ADT89-RIPE
                  tech-c: TTE2-RIPE
                  nic-hdl: ATdE1-RIPE
                  mnt-by: MAINT-TdE
                  abuse-mailbox: nemesys@telefonica.es
                  source: RIPE # Filtered

                  role: Tecnicos Telefonica de Espana
                  address: Emilio Vargas, 4
                  address: 28043-MADRID
                  address: SPAIN
                  org: ORG-TDE1-RIPE
                  admin-c: TTE2-RIPE
                  tech-c: TTE2-RIPE
                  nic-hdl: TTdE1-RIPE
                  mnt-by: MAINT-TdE
                  abuse-mailbox: nemesys@telefonica.es
                  source: RIPE # Filtered

                  % Information related to '81.36.0.0/16AS3352'

                  route: 81.36.0.0/16
                  descr: RIMA (Red IP Multi Acceso)
                  origin: AS3352
                  mnt-by: MAINT-TdE
                  source: RIPE # Filtered
                  "Beware of he who would deny you access to information, for in his heart he dreams himself your master" - Commissioner Pravin Lal.

                  Comment


                  • #10
                    Is this your ISP? Tecnicos Telefonica de Espana.
                    If you don't recognize, maybe you should utilize that abuse mailbox. Or do a Google and then report, or not.
                    Life is not measured by the number of breaths you take, but by the moments that take your breath away.
                    "Hating America is something best left to Mobius. He is an expert Yank hater.
                    He also hates Texans and Australians, he does diversify." ~ Braindead

                    Comment


                    • #11
                      I'd keep blocking and report them. There's no guarantee it will have any luck, being in what appears to be a 4th world country.
                      Life is not measured by the number of breaths you take, but by the moments that take your breath away.
                      "Hating America is something best left to Mobius. He is an expert Yank hater.
                      He also hates Texans and Australians, he does diversify." ~ Braindead

                      Comment

                      Working...
                      X