Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 21, 2008, 09:34:38 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
184898
Posts
21467
Topics
52061
Members
Latest Member:
gafanhoto-san
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v3
Windows Operating System / System Idle Process in Logs [Merged Threads]
« previous
next »
Pages:
[
1
]
2
3
...
19
Author
Topic: Windows Operating System / System Idle Process in Logs [Merged Threads] (Read 13887 times)
Bros
Newbie
Offline
Posts: 23
Windows Operating System / System Idle Process in Logs [Merged Threads]
«
on:
November 20, 2007, 04:13:05 PM »
I recently installed comodo firewall 3 and while looking through the new gui i suddenly notice a lot of connection blocked i check the log and its all a bunch of incoming tcp from seemingly random ip's for system idle proccess
what can this be?
Additional Information:
comodo firewall version:3.0.1
os: windows xp sp2
internet: adsl shared through home lan
other secuirty program: avast antivirus 4.7.1074
permissions level: admin
«
Last Edit: November 23, 2007, 10:18:23 PM by Soyabeaner
»
Logged
Goose18
Comodo's Hero
Offline
Posts: 1083
Re: HELP: Loads of strange connection blocks
«
Reply #1 on:
November 20, 2007, 04:53:49 PM »
I also am getting around 100 of these alerts too.. wonder if anyone knows why?
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 6863
Akagi
Re: HELP: Loads of strange connection blocks
«
Reply #2 on:
November 20, 2007, 04:57:14 PM »
I got them as well, but I disabled the logging on it
. Depending on how you set your rules (I shouldn't have picked expert on everything
), the application rules now have the ability to log blocked connection attempts.
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Windows Operating System / System Idle Process in Logs [Merged Threads]
«
Reply #3 on:
November 21, 2007, 01:40:46 AM »
Don't remember seeing this in Beta, but I'm getting a lot of blocked inbound connection from various IP's to SIP. Any thoughts?
«
Last Edit: December 20, 2007, 10:46:53 AM by Japo
»
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 3641
I'm not grumpy, just misunderstood.
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #4 on:
November 21, 2007, 02:38:16 AM »
Really? I've always had blocks against System Idle in probably every release. Although Egemen might have said.. I'm vague on this. I've asked previously what it was, but I can't remember if I got an answer. It's not reference in the Help. I've assumed, up to now, that System Idle means "no associated process".. and/or maybe a Global Block.
Logged
XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #5 on:
November 21, 2007, 02:43:56 AM »
Hi Kail, I guess the block does come under the Global Rule, but I'm curious as to what, exactly, it's doing. I've never seen this in any firewall I've used. Almost as soon as I logged on to the Net, I got inundated with these block events.
I've put Wireshark on the case, maybe it'll reveal something.
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
ocky
Comodo Loves me
Offline
Posts: 110
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #6 on:
November 21, 2007, 06:20:35 AM »
Have just installed and am also seeing plenty System Idle Process blocks. Even testing at
Shields Up (via dial-up to bypass router), shows all the Shields Up source ports as SIP blocks.
Logged
shinobiteno
Comodo Family Member
Offline
Posts: 54
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #7 on:
November 21, 2007, 07:16:48 AM »
AFAIK SIP is only required to be configured for tunneling and can be safely blocked for other things.
Always blocked it, since it always tried to make outbound DHCP calls to some unknown(for me) locations.
Logged
Marvin Heemeyer - True Hero!
ahuramazda
Newbie
Offline
Posts: 4
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #8 on:
November 21, 2007, 04:42:01 PM »
I'm also getting this "system Idle process" blocked in my log for version 3. I've never seen it in any firewalls I've used either. What does it do and what is it blocking?
Logged
AuraWolf
Newbie
Offline
Posts: 6
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #9 on:
November 21, 2007, 05:04:43 PM »
I've noticed this as well. The SIP from what I understand has to do with process' in your own computer, nothing with the internet. Under Firewall-Advanced-Network Security Policy the system is outgoing only and blocks unmatching requests. I don't know what it means but I, personally, don't think it's going to hurt the system.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 665
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #10 on:
November 21, 2007, 05:43:56 PM »
If you look at the TaskManager processes window, SIP is the process that nominally uses all the system resources that are not being used by other processes. I think it is a RAM scavenger, picking up RAM from other processes as a housekeeping action. I don't get the blocks on my system, but I have configured it for local and multicasting privileges. The multicasting IP range is from 224.0.0.0 to 224.0.0.255 and 239.0.0.0 to 239.255.255.255 for local multicasting and 224.0.1.0 to 238.255.255.255 for Internet multicasting. If you are seeing remote IP's not in the multicasting range, you should try stealthing your ports. There is also the possibility of torrent servers polling your computer to see if it is available and probably others that I know nothing about.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #11 on:
November 21, 2007, 06:07:40 PM »
'System Idle Processes' reflects the percentage of time your Processor has nothing to do, that's all. Generally this value has a high value 90 plus.
I can see no reason why this process should be trying to connect to the Internet, as it's a local system process.
As I said the IPs and ports it's attempting to connect to are totally random. I don't use P2P or IM...
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3321
Sometimes words are meaningless indeed...
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #12 on:
November 21, 2007, 07:32:48 PM »
What those entries look like?
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #13 on:
November 21, 2007, 08:13:11 PM »
Hi gibran, here's a couple.
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
ice
Newbie
Offline
Posts: 4
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #14 on:
November 21, 2007, 08:15:49 PM »
I have the same problem like Toggie.
Logged
Tags:
strange connection
blocks
lots of block
system idle proccess
strange block
Pages:
[
1
]
2
3
...
19
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.238 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com