Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 26, 2013, 04:07:04 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664111
Posts
70640
Topics
145274
Members
Latest Member:
brownbotm
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
Seven x64 & svchost [Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: Seven x64 & svchost [Resolved] (Read 3988 times)
burebista
Comodo's Hero
Offline
Posts: 642
Seven x64 & svchost [Resolved]
«
on:
September 18, 2009, 12:31:49 PM »
A couple of days ago I've installed Seven x64 RTM and until yesterday I have only his firewall active.
Yesterday since new CIS was out obvious that I've installed it (only FW and D+ both in Safe mode) and ditch Seven's firewall. Today I've take a look in log and I was shocked about svchost blocked events. A couple of thousand attempts on port 64527 in just a couple of hours.
I have utorrent but it's on port 55555 and when I close utorrent I receive some block attempts but by System and port 55555 and no way by svchost and port 64527.
I've scanned my system with MBAM, SAS and Sophos Anti Rootkit but I'm clean.
I've attached CIS main window with settings and intrusion attempts and another screenshot with svchost settings maybe someone have an idea because I have no idea why svchost is listening on that port.
Thanks.
CIS_main.jpg
(82.35 KB, 796x552 - viewed 8 times.)
CIS_svchost.jpg
(218.24 KB, 1109x886 - viewed 12 times.)
«
Last Edit: September 19, 2009, 05:29:33 PM by Quill
»
Logged
If it ain't broke... fix it until it is.
burebista
Comodo's Hero
Offline
Posts: 642
Re: Seven x64 & svchost
«
Reply #1 on:
September 19, 2009, 02:20:53 AM »
OK, a new day with new data.
Last night was a nightmare, after 10 hours since my Power On I have more than 10,000 blocked "intrusions" on svchost and that port 64527. I've scanned (full) with Kaspersky on-line and I'm clean (of course).
Now in the morning I've opened my computer to see first screenshot and no alerts after one hour of browsing (utorrent closed). I was curious why and I want to see what's with 213.199.162.214 and for my relief it's teredo.ipv6.microsoft.com and and a
stroke my head, it seems that all that blocked traffic has something to do with utorrent Teredo/IPv6.
I know that CIS is not a IPv6 FW so now my question is should I allow svchost outbound traffic (I guess the answer is yes) but more important is should I allow svchost inbound ONLY for that 64527 port?
Thanks in advance.
CIS_startup.png
(17.26 KB, 660x451 - viewed 7 times.)
CIS_MS.png
(13.79 KB, 403x269 - viewed 4 times.)
Logged
If it ain't broke... fix it until it is.
bulgroz
Comodo's Hero
Offline
Posts: 366
Re: Seven x64 & svchost
«
Reply #2 on:
September 19, 2009, 04:55:55 AM »
Quote from
http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Quote
Dynamic and/or private ports: 49152–65535
By definition, no ports can be registered in the dynamic range.[1]
I would be tempted to block traffic on that port and see if all is well. Being a private port, it makes it hard to research.
Cheers
Logged
burebista
Comodo's Hero
Offline
Posts: 642
Re: Seven x64 & svchost
«
Reply #3 on:
September 19, 2009, 05:00:21 AM »
Everything is well with that port blocked but I have "only" 10,000 alerts.
Now I've opened it for testing and everything looks well again but without any intrusion alerts.
So keep it open on close it, that's the question?
Thanks for you reply.
Logged
If it ain't broke... fix it until it is.
Toggie
Guest
Re: Seven x64 & svchost
«
Reply #4 on:
September 19, 2009, 05:22:02 AM »
Hi burebista
If you're using a router with NAT, what you're seeing is dynamic Teredo NAT port mapping. Basically, when a request is sent to a Teredo server through a NAT the last 32 bits of the IPv6 address are mapped to the dynamic IPv4 NAT port, in your case 64527.
What I'm not sure about is why you have so many log entries...
Logged
burebista
Comodo's Hero
Offline
Posts: 642
Re: Seven x64 & svchost
«
Reply #5 on:
September 19, 2009, 06:21:51 AM »
Hi
Quill
I'm not under a router but direct cable modem access.
About those log entries I believe that it's similar with IPv4 when I close utorent because then I see a lot of entries blocked by System and utorent port (55555 in my case) and none if I don't launch utorent all day. Now with utorrent closed (after opening it for a while) I have those additional entries with svchost and port 64527.
So my basic question is if I can leave port 64527 open for incoming connections for svchost? I know that CIS don't do Stateful Inspection for IPv6 and I'm not sure if I'm safe with that port open.
As you see I can have some IPv6 connections in utorrent. Rare but they exist.
BTW on my previous Vista64 SP2 install and same utorrent version and port (55555) I didn't have those svchost entries (IPv6 enabled too in Vista) so that's why I was surprised by those new blocked entries for svchost.
Thanks again for your response.
utorrent_ipv6.png
(16.53 KB, 728x129 - viewed 6 times.)
«
Last Edit: September 19, 2009, 06:25:59 AM by burebista
»
Logged
If it ain't broke... fix it until it is.
Toggie
Guest
Re: Seven x64 & svchost
«
Reply #6 on:
September 19, 2009, 06:52:18 AM »
It is slightly curious. Certainly, you are sending requests is teredo.ipv6.microsoft.com (213.199.162.214) which is outbound from you on port 64527, so that is likely the return endpoint.
When I use uTorrent with Ipv6 the connections are made on my designated uTorrent port, but then I don't use teredo, so there may be some difference there.
You could try a quick experiment, just disable teredo for a short time and note any differences, then re-enable. To disable, open a command prompt:
netsh interface teredo set state disabled
to re-enable:
netsh interface teredo set state client
Logged
burebista
Comodo's Hero
Offline
Posts: 642
Re: Seven x64 & svchost
«
Reply #7 on:
September 19, 2009, 07:03:37 AM »
Quote from: Quill on September 19, 2009, 06:52:18 AM
You could try a quick experiment, just disable teredo for a short time and note any differences
OK, did that but what differences should I look for?
All I can see is that svchost don't listen anymore on 64527 and all IN/OUT requests for thet port are gone.
No blocked events recorded for svchost and 64527 too.
So for my peace of mind it's better to leave Teredo interface disabled?
svchost_teredo_closed.png
(17.66 KB, 660x451 - viewed 3 times.)
«
Last Edit: September 19, 2009, 07:07:15 AM by burebista
»
Logged
If it ain't broke... fix it until it is.
Toggie
Guest
Re: Seven x64 & svchost
«
Reply #8 on:
September 19, 2009, 07:59:02 AM »
Unless you feel you really need Teredo, I'd say go without. As it stands, it's difficult to implement any real control over what IPv6 does via the firewall.
If you feel you need IPv6 support, first check the status of your ISP to see if they offer native support. Failing that register a free account with a tunnel broker such as Hurricane Electric. They will give you a free 6in4 (not 6to4) tunnel that will allow control of the endpoints.
Personally, I feel giving processes such as svchost and system full outbound access is way to liberal. What you have seen is just one small example of that.
Logged
burebista
Comodo's Hero
Offline
Posts: 642
Re: Seven x64 & svchost
«
Reply #9 on:
September 19, 2009, 08:45:23 AM »
Thanks a lot for your advices.
From my point of view case closed, I'll live without Teredo and I'll try to tighten svchost rule.
You can close thread since is resolved.
Logged
If it ain't broke... fix it until it is.
Toggie
Guest
Re: Seven x64 & svchost
«
Reply #10 on:
September 19, 2009, 05:29:06 PM »
You're welcome. Just PM a mod if you wish to re-open the thread
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.058 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com