Welcome, Guest. Please login or register.
September 05, 2008, 01:14:34 PM

Login with username, password and session length

188669 Posts
22008 Topics
52794 Members

Latest Member: chmielu

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Closed app - logged attempts - honest...
« previous next »
Pages: [1] Go Down Print
Author Topic: Closed app - logged attempts - honest...  (Read 545 times)
Comofo
Guest
« on: May 10, 2008, 11:06:53 PM »

Came home today and checked my CFP log and saw two allowed UDP packets from Utorrent.exe (which I haven't run in weeks) from my static ip [port 1690] to my DNS server [53].
Other than AV and Comodo no other apps were running at all.
Can anyone explain this anomaly? 

As always,
thank you very much for your time.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 441


Spy


« Reply #1 on: May 11, 2008, 02:02:32 AM »

I think you should ask yourself who else have access to your PC while you are not at home...
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Comofo
Guest
« Reply #2 on: May 11, 2008, 02:25:57 AM »

I know, I know - it sounds crazy, but no one was here. Two packets in a row, within a minute of each other, no applications running - no one home.

If I didn't see it, I wouldn't believe it either. It's crazy.

Had me trippin' so hard - I've since ran every single scan under the sun (Avira, F-secure, SAS, Kaskpersky, on and on...). I have no idea what the frick transpired...
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 441


Spy


« Reply #3 on: May 11, 2008, 02:54:02 AM »

Weird indeed, temp solution will be to change action from Allow to Block for torrent rules while you do not using App.
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Comofo
Guest
« Reply #4 on: May 11, 2008, 04:06:40 AM »

I usually Remove the rules completely (and a few others) when I'm not using it - then when I fire it up I just "treat as" Utorrent PreDefSecPolicy...and the one time I don't : guess what.

I am stymied, and since it defies logic - there's probably no logical explanation.

If someone told me that their phone rang while it was off the hook, I wouldn't know what to tell them either  - and would probably suspect stupidity, insanity or some hybrid.

I guess I was hoping for an "Oh, that? That happens every so often when blah blah blah" 

I swear to FSM it really happened Angel
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.249 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com