Announcement

Collapse
No announcement yet.

Security junkies, some help?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Security junkies, some help?

    So I've been having some odd internet connectivity issues with my PC the last month or so. About once a week, give or take, I come home to find my computer's been disconnected from the internet for several hours, not saying much in computer management (or at least the parts I know to access), but reporting a Winsock error somewhere or another (I forget what tells me Winsock, but it's not part of XP, it's probably my wireless connection or DynDNS updater or some such).

    Could just be the odd XP meltdown, particularly since I don't reboot my computer terribly often. I can't repair the connection, and I can't restore it through ipconfig. Rebooting clears it fine.

    However, two separate times (the two most recent) I've tried Netstat, initially randomly just as another check to see if something's locking up... and I get a rundown of every port on my computer, all in "CLOSE/WAIT" status, listing a single IP (both times the same root host, 208.113, which resolves to dreamhost.com). For every port from some low number to 5000.

    My firewall doesn't show anything particularly interesting (at least that I would recognize as interesting). It shows a lot of events, but I think they're all fine [people connecting to my pitboss hosted games].

    What does this mean? Should I be worried about this? Why doesn't my firewall say anything at all about it [it doesn't even show a single listing of the IP address in the log]?

    My scanner doesn't see anything suspicious or even particularly dangerous... so I don't think i'm infected by anything [and I don't download anything remotely dangerous, so I'm not at a very high risk either].

    Any ideas??

    My setup btw is my computer has a wireless connection with a wireless router, which connects directly to a DSL modem. My computer isn't DMZed or otherwise passed through the wireless router's firewall, except for about 30 specific ports for Civ and sports games set on port triggering (plus the usual permissions for normal ports). The wireless router uses 64 bit WHK encryption, with a semirandom key (not a word, and not guessable except by brute force). There is one other computer on the LAN, but it was not turned on at the time of the disconnection.
    Last edited by snoopy369; June 22, 2007, 04:11.
    <Reverend> IRC is just multiplayer notepad.
    I like your SNOOPY POSTER! - While you Wait quote.

  • #2
    Anybody have an idea?
    <Reverend> IRC is just multiplayer notepad.
    I like your SNOOPY POSTER! - While you Wait quote.

    Comment


    • #3
      Sounds like the kids have gotten a hold of it.
      “As a lifelong member of the Columbia Business School community, I adhere to the principles of truth, integrity, and respect. I will not lie, cheat, steal, or tolerate those who do.”
      "Capitalism ho!"

      Comment


      • #4
        Same thing I always suspect, malware.
        Life is not measured by the number of breaths you take, but by the moments that take your breath away.
        "Hating America is something best left to Mobius. He is an expert Yank hater.
        He also hates Texans and Australians, he does diversify." ~ Braindead

        Comment


        • #5
          No kids... and no malware I can see, anyway.

          UH on that other forum told me Civstats might be responsible, so we'll see if that's the case next time it crashes
          <Reverend> IRC is just multiplayer notepad.
          I like your SNOOPY POSTER! - While you Wait quote.

          Comment


          • #6
            Originally posted by snoopy369
            No kids... and no malware I can see, anyway.
            Well, that complicates things.
            “As a lifelong member of the Columbia Business School community, I adhere to the principles of truth, integrity, and respect. I will not lie, cheat, steal, or tolerate those who do.”
            "Capitalism ho!"

            Comment

            Working...
            X