Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 02:34:02 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664071
Posts
70633
Topics
145263
Members
Latest Member:
freefirecauldron
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
General Security Questions and Comments
is someone trying to hack my pc??? [Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: is someone trying to hack my pc??? [Resolved] (Read 8985 times)
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
is someone trying to hack my pc??? [Resolved]
«
on:
August 07, 2007, 08:08:01 AM »
I see many logs in comodo firewall about access being denied to a ip for "inbound policy violation"
does that mean that ip is trying to access my pc???
see the attached image.....
http://i11.tinypic.com/6gkh6z4.jpg
plz help
«
Last Edit: August 08, 2007, 08:47:30 AM by Little Mac
»
Logged
blackbinary
Newbie
Offline
Posts: 4
Re: is someone trying to hack my pc???
«
Reply #1 on:
August 07, 2007, 12:13:53 PM »
I highly doubt it. If your computer has any mal-ware on it, it's probably that outside company etc. that is trying to contact it. Otherwise, it can easily be just useless junk that gets sent no-matter what. Even when i built my PC, just installed Comodo, plugged in the internet, and whammo. Alot of blocks there too. I guess it really depends just how many you are getting. If its 10+ a minute, you might have a problem, MAYBE. Again, if you block alot of programs, or on the other end, don't allow alot of programs yet, that could be responsible.
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #2 on:
August 07, 2007, 01:46:27 PM »
Looks like a UPnP multicast, possibly from a router. Are you behind a router? Any port-forwarding set on the router?
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
Re: is someone trying to hack my pc???
«
Reply #3 on:
August 07, 2007, 02:53:31 PM »
Quote
Looks like a UPnP multicast, possibly from a router. Are you behind a router? Any port-forwarding set on the router?
LM
Yes....I am behind a router.....
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #4 on:
August 07, 2007, 03:16:16 PM »
Quote from: ashu on August 07, 2007, 02:53:31 PM
Yes....I am behind a router.....
Can you identify the IP involved... 192.168.1.3?
This is an internal IP address (ie, on a network/behind a router). In this scenario, there's often a lot of multicast "chatter." The Destination IP address is a part of the subnet that is typically reserved/only used for multicast traffic (typically IGMP) - that being the 239.255.255.250 address.
The 192.168.1.3 IP would be another computer on your network/LAN, or perhaps a resource like a shared/networked printer, storage device, server, etc. Thus, I would try to make sure that I knew what the device was.
Also, is your router (and thus, the network) wireless?
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
Re: is someone trying to hack my pc???
«
Reply #5 on:
August 07, 2007, 03:34:25 PM »
Quote
The 192.168.1.3 IP would be another computer on your network/LAN, or perhaps a resource like a shared/networked printer, storage device, server, etc. Thus, I would try to make sure that I knew what the device was.
Yes i think you are right....its a computer cuz its in the range of my ip (192.168.x.x)......
also, i think, its a computer cuz we don't have shared printer/storage device on our network....
but is it possible that the ip is trying to access my pc???
Quote
Also, is your router (and thus, the network) wireless?
No..
«
Last Edit: August 07, 2007, 03:38:13 PM by ashu
»
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #6 on:
August 07, 2007, 03:45:52 PM »
Quote from: ashu on August 07, 2007, 03:34:25 PM
but is it possible that the ip is trying to access my pc???
I doubt it. Looks like network multicast traffic, based on UPnP and SSDP services being enabled in Windows. Think of it this way... the computers on the LAN are like blindfolded people in a room together. One wants to know if anyone named "Joe" is in the room, so they yell, "Hey, is Joe in here?" Everybody hears it, but most ignore it. The person yelling hopes that Joe will answer if he's there. Same sort of thing. Computers on the LAN that have UPnP & SSDP services active want to know if there are any UPnP devices or computers out there. So they "shout" to see if they get a response.
If someone were trying to gain access, you'd likely see some more log entries than a few on those types of ports. It's always
possible
that something is going on, but not very likely in my opinion.
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
Re: is someone trying to hack my pc???
«
Reply #7 on:
August 07, 2007, 03:48:31 PM »
Wait take a look at this.........
A different ip this time......and it doesn't seems to belong my network.....
I got several "inbound policy violation" logs from this ip as well...
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #8 on:
August 07, 2007, 03:54:25 PM »
That's NetBIOS traffic (another Windows service to be disabled, along with UPnP & SSDP...). The ports (137, 138) give it away. Again, very common, especially on networks.
The 169.x.x.x IP is an "error" IP; non-routable, and the result of not having an active internet connection/IP address established when the traffic was experienced. You note that both Source & Destination IPs are 169.x.x.x.
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
Re: is someone trying to hack my pc???
«
Reply #9 on:
August 07, 2007, 03:59:28 PM »
thanks little mac for your great help.......
'am completely a newbie to networking and stuff......thanks a lot...
.
so is there anything to worry about ?
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #10 on:
August 07, 2007, 04:12:29 PM »
I really don't think so. Here's the thing to boost your confidence... Even if it is someone trying to access your computer, it is being blocked, as you can clearly see from the logs.
But I really don't think that's what it is; I think it's simply network chatter. It can certainly fill up your logs, though.
If you want to clear that out of the logs, you can create a simple rule in Network Monitor. This is fine to do, as you already know they're blocked and it's not impacting your connectivity.
Open Network Monitor. Go to the very bottom rule (the Block & Log IP In/Out rule). Right-click and select "Add/Add Before." This is how the rule will look:
Action: Block (but don't check the box to create an alert - that would cause the rule to be logged)
Protocol: TCP/UDP
Direction: In
Source IP: Any
Destination IP: Any
Source Port: Any
Destination Port: A Set of Ports: 137,138,1900 (no space after the comma)
OK. Reboot.
That should help significantly.
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
ashu
Comodo Family Member
Offline
Posts: 91
Better burnout than fade away...
Re: is someone trying to hack my pc???
«
Reply #11 on:
August 07, 2007, 11:11:02 PM »
Thanks my friend, you were great help........
ashu
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: is someone trying to hack my pc???
«
Reply #12 on:
August 08, 2007, 08:47:04 AM »
Glad to help, ashu. I'll mark the topic as resolved, and close it. If you need it reopened, just PM a Moderator (please include a link back here) and we'll be glad to do so.
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.045 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com