Welcome, Guest. Please login or register.
September 07, 2008, 07:49:15 PM

Login with username, password and session length

189570 Posts
22065 Topics
52908 Members

Latest Member: aldodolci

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Intrusions
« previous next »
Pages: [1] Go Down Print
Author Topic: Intrusions  (Read 379 times)
speedosurfer
Comodo Member
**
Offline Offline

Posts: 36


« on: May 14, 2008, 05:58:38 AM »

 ???i found out that Comodo Firewall 3.0 is blocking 576 intrusions this a lot where can i found information about the intrusions is there an event file/log it never warns that it has blocked intrusions.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #1 on: May 14, 2008, 06:09:43 AM »

90% of firewall don't warn you. Of course there is a log. Go to firewall\firewall events. What are your global rules? Are you behind a hardware firewall?
Logged
speedosurfer
Comodo Member
**
Offline Offline

Posts: 36


« Reply #2 on: May 14, 2008, 06:36:45 AM »

i am not behind an hardware firewall i use adsl and use an Fritz Box fon WLAN modem/router and i don't know of there is an build-in firewall. The intrusions/blocks are on remoteport 14013 and igmp and icmp, i use the standard global rules delivered with Comodo Firewall i have only disabled netbios udp/tcp local and remote.
I use Comodo Firewall 3.0, Avira Premium Anti-Virus and A-Squared anti-malware have you any idea where the intrusions come from. See also the attachement and thanks for your help
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #3 on: May 14, 2008, 07:17:59 AM »

If you have a router then you need to be sure your hardware firewall is enabled properly. That is your first line of defense. Dont save something to an html view. Save it has a jpeg or something. Those are mainly Windows blocks. What are your global rules again? What are your rules for Windows and and other things like System or Explorer? What does your global rule say? "Block all incoming connections"? Or something else?
« Last Edit: May 14, 2008, 07:28:50 AM by Vettetech » Logged
speedosurfer
Comodo Member
**
Offline Offline

Posts: 36


« Reply #4 on: May 14, 2008, 07:59:17 AM »

hello i have made an printscreen of the global rules i have nothing change to other predifined rules i download comodo and thats it
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #5 on: May 14, 2008, 08:07:57 AM »

You must have run the stealth port wizard and selected the option to block all incoming connections cause the default global rule is block all echo ping,something like that. The reason for your intrusions is cause of your global rules. What are your firewall rules for Windows? Again I ask if your router has a hardware firewall cause most of them do. I have a hardware firewall which blocks all my inbounds so I do not need a global rule to block all incoming connections.
Logged
speedosurfer
Comodo Member
**
Offline Offline

Posts: 36


« Reply #6 on: May 15, 2008, 08:54:16 AM »

where can i find the windows rules for the firewall
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #7 on: May 15, 2008, 09:11:54 AM »

Go to Firewall\Advanced\Network Security Policy. Once again I will ask is your router firewall on?
Logged
speedosurfer
Comodo Member
**
Offline Offline

Posts: 36


« Reply #8 on: May 15, 2008, 09:59:13 AM »

Yes the firewall on the router is on but you can't change anything very strange i have asked mine ISP for support and they will react in 3 days so the internal firewall seems to be on and active.

The windows rules are standing in the global rules i understand i have made 2 screenshots for you maybe you can help me.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #9 on: May 15, 2008, 10:09:17 AM »

See this post and screen shots. Dont wait for your ISP. You can get into your router settings by typing something like 192.168.1 into your address bar. Just Google your router and you will find out.

http://forums.comodo.com/help_for_v3/windows_operating_system_system_idle_process_in_logs_merged_threads-t14948.0.html
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4567



« Reply #10 on: May 15, 2008, 10:16:50 AM »

I honestly don't need a software firewall cause my modem is fully stealthed and blocks all incoming connections. I use Comodo for the program control and HIPS features.
Logged
grue155
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 932


« Reply #11 on: May 18, 2008, 05:42:18 PM »

I've taken a fast eyeball at your log. It looks like some process running on your PC is trying to talk to your router, and CFP is blocking the replies. The process that is running on your PC is using port 14013, and all the router replies are trying to answer back to that port. That's why you're seeing all the destination port logs for that one port. The fact the the source ports are changing (and in an increasing sequential manner) is typical for "status query"-like traffic.

If you use a "netstat -anob" from a PC command prompt, you should see some process running that using port 14013. Once that process gets identified, then it will be possible to figure out what rules need to be changed.

The ICMP and IGMP traffic that is in your log, looks to be normal router-to-PC type traffic. IGMP in particular gets used with Windows UPnP. From your log, these don't seem to be anything to be concerned about, for now.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.256 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com