Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 17, 2010, 08:11:51 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
372309
Posts
41248
Topics
93896
Members
Latest Member:
billc.cn
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
A lot more blocked intrusion attempts with CIS 310...531
« previous
next »
Pages:
[
1
]
Author
Topic: A lot more blocked intrusion attempts with CIS 310...531 (Read 834 times)
donnyd
Comodo Loves me
Offline
Posts: 135
A lot more blocked intrusion attempts with CIS 310...531
«
on:
July 09, 2009, 10:45:58 AM »
I'm getting a lot more network blocked intrusion attempts with CIS 310 all coming from application Windows Operating System. The protocol is UDP and the destination port and source port all seem to be either 137 or 138. Is there something I need to tweak or is this a true intrusion? I'm running Windows XP media center SP4 and only CIS for security.
Logged
bluesjunior
Comodo's Hero
Offline
Posts: 388
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #1 on:
July 09, 2009, 01:12:54 PM »
I am getting the same but mine is mostly from ports 445 and to a lesser extent 135. From what I understand ports 137 and 138 are all linked. My daughters boyfriend said something about these ports and NetBios but his explanation was a bit too techy for me to comprehend and I would like to find out a bit more about the subject before I go switching off NetBios if this is indeed the solution to this problem.
Logged
Dch48
Comodo's Hero
Offline
Posts: 1068
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #2 on:
July 09, 2009, 01:29:51 PM »
Quote from: donnyd on July 09, 2009, 10:45:58 AM
I'm getting a lot more network blocked intrusion attempts with CIS 310 all coming from application Windows Operating System. The protocol is UDP and the destination port and source port all seem to be either 137 or 138. Is there something I need to tweak or is this a true intrusion? I'm running Windows XP media center SP4 and only CIS for security.
SP4? where did you get that?
Logged
HP dv5215us Laptop
Turion64 ML-34 1.8ghz single core, 2g RAM, 10 meg cable connection
XP Professional SP3, IE8 & Outlook Express
CIS 4.0 full (Firewall:Safe - D+:Clean PC - AV:Stateful - Sandbox:disabled)
MBAM & SAS On Demand
jay2007tech
Malware Research Group
Comodo's Hero
Offline
Posts: 639
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #3 on:
July 09, 2009, 03:37:29 PM »
Quote
The protocol is UDP and the destination port and source port all seem to be either 137 or 138
I usually have over 1,000 intrusion attempts in a day (I know what and where the intrusions are coming from and there not really intrusions. It's almost all microsoft and certain software that want's to phone home
I wouldn't worry about it.
You'll generally get that feeling, if your being attacked
For windows 7, vista, and xp that I'm using. I'm blocking microsoft to the best of my ability. I'm blocking 137, 138, 139, 1900, 3544, 63351, 58226, 67, 68, 55945, 3702, and quite a bit more.
I'm also block outbound connection for windows update (I have another way to update HeHeHeHe), system, svchost(partially), WMP, explorer, ie explorer, and much more
Either way, your probally fine
If your still worried, download "hijack this" from download.com. Copy and paste the logs at the appropriate section in the forums and someone here will let you know if your good to go
«
Last Edit: July 09, 2009, 03:41:25 PM by jay2007tech
»
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Jim__
Comodo Loves me
Offline
Posts: 121
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #4 on:
July 09, 2009, 05:46:06 PM »
This is most likely broadcast messages rather that something directed to a specific IP address.
Since this traffic is being blocked anyway, you could set up a rule to block the traffic but not log it. I created a port set (137,138,139,445) and then created a rule to block incoming TCP and UDP with those ports as a destination without logging.
Logged
Xman
Guest
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #5 on:
July 09, 2009, 08:23:21 PM »
Quote from: bluesjunior on July 09, 2009, 01:12:54 PM
I am getting the same but mine is mostly from ports 445 and to a lesser extent 135. From what I understand ports 137 and 138 are all linked. My daughters boyfriend said something about these ports and NetBios but his explanation was a bit too techy for me to comprehend and I would like to find out a bit more about the subject before I go switching off NetBios if this is indeed the solution to this problem.
Hi Bluesjunior, run The first 3 tests at Shields up here:
https://www.grc.com/x/ne.dll?bh0bkyd2
when you'll finish the all service ports scan click on a port ex: 135, 139, 445 & especially 137 for in depth info on their origin and use, you'll get all the info you need.
Regards & cheers
Xman
«
Last Edit: July 09, 2009, 08:34:14 PM by Xman
»
Logged
bluesjunior
Comodo's Hero
Offline
Posts: 388
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #6 on:
July 10, 2009, 04:16:16 AM »
Thanks for the link Xman, I already knew about GRC and knew I was completely stealthed and passed all the tests but not that you could click on a port number for additional info. If I were to set a rule to block but not log for Ports 135,137,138,139 and 445 would this reduce the size of my logs. Could someone walk me through that with a step by step on how to set such a rule or is there a better solution?.
Logged
SiberLynx
Comodo's Hero
Offline
Posts: 970
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #7 on:
July 10, 2009, 05:05:20 AM »
Hi Guys,
Donnyd and Bluesjunior,
Regarding the site referred by
Xman
There is not only the test there but explanations about ports and free utilities
http://www.grc.com/freepopular.htm
For example, info about port 135 is here:
http://www.grc.com/freeware/dcom.htm
Info about Ports 137, 138,139, 445 is here
http://www.grc.com/port_137.htm
Briefly about the letter ports – you can just disable NetBIOS over TCP/IP if your have standalone computer
Just Google “disabling NetBIOS” and you find tons of advices here is MS page
http://support.microsoft.com/kb/313314
In addition Search this forum using requested ports as keywords and there are many threads here as well
Hope this helps
My regards
«
Last Edit: July 10, 2009, 05:11:29 AM by SiberLynx
»
Logged
admin; XP Pro, SP3 (32); CIS 3.14.130099.587 (firewall only; Proactive with Defense+); Vengine 2.7.0.33 ; AVG free; Mamutu Behavioural Blocker
donnyd
Comodo Loves me
Offline
Posts: 135
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #8 on:
July 10, 2009, 08:13:29 AM »
Quote from: Dch48 on July 09, 2009, 01:29:51 PM
SP4? where did you get that?
Sorry! Type-0, it's SP3....................
Logged
bluesjunior
Comodo's Hero
Offline
Posts: 388
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #9 on:
July 10, 2009, 08:29:45 AM »
Thanks for the reply SiberLynx,
My PC operating system is Windows XP Home Edition SP3, up to date using Windows Update. It is a standalone PC on a Cable Broadband account with Virgin Media here in the UK with no router and accessed by a Fast Ethernet Connection modem and is shared between me and my grown up daughter ie two accounts both with administrative authority.
I did some reading on the links and advise offered in your previous reply and have come up with two options of which I am unsure which is the best way to proceed. I would ideally like to reduce the number of intrusion attempts being recorded by Comodo CIS. Could someone have a look at the two options below and advise me on the best procedure in order to achieve the above mentioned result.
Quote
Disable NetBIOS on the DHCP server
To disable NetBIOS on the DHCP server, follow these steps:
1.Click Start, point to Programs, point to Administrative Tools, and then click DHCP.
2.In the navigation pane, expand the server_name, expand Scope, right-click Scope Options, and then click Configure Options.
Note In this step, the server_name placeholder specifies the name of the DHCP server.
3.Click the Advanced tab, and then click Microsoft Windows 2000 Options in the Vendor class list.
4.Make sure that Default User Class is selected in the User class list.
5.Click to select the 001 Microsoft Disable Netbios Option check box, under the Available Options column.
6.In the Data entry area, type 0x2 in the Long box, and then click OK.
Configure the DHCP client to enable the DHCP server to determine NetBIOS behavior
For Windows XP, Windows Server 2003, and Windows 2000
1.On the desktop, right-click My Network Places, and then click Properties.
2.Right-click Local Area Connection, and then click Properties
3.In the Components checked are used by this connection list, double-click Internet Protocol (TCP/IP), click Advanced, and then click the WINS tab.
Note In Windows XP and in Windows Server 2003, you must double-click Internet Protocol (TCP/IP) in the This connection uses the following items list.
4.Click Use NetBIOS setting from the DHCP server, and then click OK three times.
Quote
How to disable NetBIOS over TCP/IP?
In Windows 2000/XP/2003 you have the possibility to disable NetBIOS over TCP/IP. You do this by right-clicking on My Network Places and selecting Properties. Then right-click on the appropriate Local Area Connection icon, and select Properties.
Next, click on Internet Protocol (TCP/IP) and Properties.
Now click Advanced, and select the WINS tab.
There you can enable or disable NetBIOS over TCP/IP.
The changes take effect immediately without rebooting the system.
You will get an event in your event log if you do not also disable the TCP/IP NetBIOS Helper Service service. You can Disable this service in Control Panel > Administrative Tools > Services if desired.
I also downloaded a program from the GRC link called DECOMBOB which I also haven't used until I find out if it is a good idea to use it or not.
Logged
SilentMusic7
Comodo's Hero
Offline
Posts: 229
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #10 on:
July 11, 2009, 10:00:27 AM »
I have cable internet, and I too get hundreds of intrusion attempts a day from my neighbors' computers. My understanding is that most computer users are victims of viruses that listen to the network and attempt to spread themselves.
I recommend that high-speed internet users install a hardware router, with NAT and stateful packet inspection (SPI) features, for the following reasons:
1. Allows software firewall to log all blocked intrusions
2. Less loading on the computer
3. Hardware firewalls are more secure than software firewalls for attacks from neighbors
4. Allows multiple computers to share a printer without allowing infections to spread to each other
5. For times when the software firewall is disabled - during firewall upgrade, Windows installation
See other threads where Comodo CIS users complain about how CIS installation hangs without internet access, which is a case where a hardware firewall provides the only intrusion protection.
Logged
Toggie
Guest
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #11 on:
July 11, 2009, 10:24:54 AM »
Quote
I recommend that high-speed internet users install a hardware router, with NAT and stateful packet inspection (SPI) features, for the following reasons:
1. Allows software firewall to log all blocked intrusions
I'd recommend a good router too. Not sure I really understand the rest of that?
Quote
2. Less loading on the computer
I've seen no difference in 'load' on my PC since my router died.
Quote
3. Hardware firewalls are more secure than software firewalls for attacks from neighbors;
Highly debatable.
Quote
Allows multiple computers to share a printer without allowing infections to spread to each other
so does CIS?
Quote
5. For times when the software firewall is disabled - during firewall upgrade, Windows installation
Is it too hard to unplug your network cable?
Quote
See other threads where Comodo CIS users complain about how CIS installation hangs without internet access, which is a case where a hardware firewall provides the only intrusion protection.
See the many threads where people are happy and have no such problems.
Logged
donnyd
Comodo Loves me
Offline
Posts: 135
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #12 on:
July 11, 2009, 10:48:57 AM »
Quote from: bluesjunior on July 10, 2009, 08:29:45 AM
Thanks for the reply SiberLynx,
My PC operating system is Windows XP Home Edition SP3, up to date using Windows Update. It is a standalone PC on a Cable Broadband account with Virgin Media here in the UK with no router and accessed by a Fast Ethernet Connection modem and is shared between me and my grown up daughter ie two accounts both with administrative authority.
I did some reading on the links and advise offered in your previous reply and have come up with two options of which I am unsure which is the best way to proceed. I would ideally like to reduce the number of intrusion attempts being recorded by Comodo CIS. Could someone have a look at the two options below and advise me on the best procedure in order to achieve the above mentioned result.
I also downloaded a program from the GRC link called DECOMBOB which I also haven't used until I find out if it is a good idea to use it or not.
I read your post and went ahead and set my PC to the latter of the two mentioned and since then I have not received any logged intrusion attempts related to NetBIOS and ports 137,138 :
How to disable NetBIOS over TCP/IP?
In Windows 2000/XP/2003 you have the possibility to disable NetBIOS over TCP/IP. You do this by right-clicking on My Network Places and selecting Properties. Then right-click on the appropriate Local Area Connection icon, and select Properties.
Next, click on Internet Protocol (TCP/IP) and Properties.
Now click Advanced, and select the WINS tab.
There you can enable or disable NetBIOS over TCP/IP.
The changes take effect immediately without rebooting the system.
You will get an event in your event log if you do not also disable the TCP/IP NetBIOS Helper Service service. You can Disable this service in Control Panel > Administrative Tools > Services if desired.
Logged
SiberLynx
Comodo's Hero
Offline
Posts: 970
Re: A lot more blocked intrusion attempts with CIS 310...531
«
Reply #13 on:
July 11, 2009, 11:34:03 AM »
Quote from: SilentMusic7
See other threads where Comodo CIS users complain about how CIS installation hangs without internet access
Quote from: Toggie
See the many threads where people are happy and have no such problems
that is true, Toggie.
SilentMusic7, I am not saying that such threads don't exist, I just never came across those.
But I must say I did many clean reinstalls being completely disconnected. Only few small online updates were done when I am “in the mood”
That is one of the greatest thing in Comodo Firewall that you can do installation being disconnected and I hope the will not change. I always disconnecting; properly shutting down all other security (not just from “sysTray right-click”) … no services , no startups etc. Then I am rebooting; unistalling; checking the registry and cleaning if necessary (using my preferred set of Search Tools and Cleaners); then installing the new one.
I never had a problem and conflicts except one old case where there was a bug in uninstaller and the device was left behind, which I missed at first (rather overlooked). That was fixed now.
So, installations without connection and other security around is the most preferable way in my opinion.
Sure I am talking about Firewall only, I don't know whether Antivirus requires the connection being alive.
Cheers!
Logged
admin; XP Pro, SP3 (32); CIS 3.14.130099.587 (firewall only; Proactive with Defense+); Vengine 2.7.0.33 ; AVG free; Mamutu Behavioural Blocker
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in -0 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com