Welcome, Guest. Please login or register.
October 12, 2008, 10:40:28 PM

Login with username, password and session length

199786 Posts
22932 Topics
55032 Members

Latest Member: noebro

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  What are these firewall events? (screenshots)
« previous next »
Pages: 1 2 [3] 4 5 Go Down Print
Author Topic: What are these firewall events? (screenshots)  (Read 4650 times)
LirvA
Comodo's Hero
*****
Offline Offline

Posts: 214



« Reply #30 on: May 05, 2008, 01:35:23 AM »

"No, on both sides are your own IP address, but your first picture on this tread is "fishy""


This one?
Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #31 on: May 05, 2008, 01:42:30 AM »

Sorry, it is not your IP on both side.
Yes like something scanning your ports: 80, 443 etc.
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Xw
Newbie
*
Offline Offline

Posts: 22


« Reply #32 on: May 05, 2008, 01:48:26 AM »

Hi,
When I'm using Stealth Ports Wizard to block all incoming (behind a routeur, but no trouble)

I've these firewall events, is it normal ?

Ty

edit :This happens only when I'm surfing (firefox, ie ....)
« Last Edit: May 06, 2008, 04:10:59 PM by Xw » Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #33 on: May 05, 2008, 01:50:54 AM »

172.133.58.119
AC853A77.ipt.aol.com
Host unreachable

172.128.0.0 - 172.191.255.255

America Online
22000 AOL Way
Dulles
VA
20166
United States

America Online, Inc.
+1-703-265-4670
domains[ at ]aol.net

Abuse:
+1-703-265-4670
abuse[ at ]aol.net

DAHA-01.NS.AOL.COM
DAHA-02.NS.AOL.COM
DAHA-07.NS.AOL.COM

AOL-172BLK
Created: 2000-03-24
Updated: 2003-08-08
Source: whois.arin.ne

Sorry, must sleep now, see you
« Last Edit: May 05, 2008, 01:57:17 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo's Hero
*****
Offline Offline

Posts: 214



« Reply #34 on: May 05, 2008, 01:57:35 AM »

I looked up the 205.188.146.145 that was in question in the 3rd screenshot you mentioned I might need to allow if it was my ISP's, this is the return:

205.188.146.145

Hostname

      nstot.proxy.aol.com

Geo-Location Information

      Country   United States
      State/Region   
      City   
      Latitude   38
      Longitude   -97
      Area Code   0
Logged

"I hate myself and want to die" - Kurt Cobain
LirvA
Comodo's Hero
*****
Offline Offline

Posts: 214



« Reply #35 on: May 05, 2008, 02:01:10 AM »

Thank you salmonela, certainly.

I think that IP is an AOL proxy?

In that cause I should allow this path that was blocked then, correct?


C:\WINDOWS\system32\svchost.exe - Source IP: 172.167.102.167 - source port: 2028 - Destination IP: 205.188.146.145 - Destination port 53
Logged

"I hate myself and want to die" - Kurt Cobain
Comofo
Guest
« Reply #36 on: May 05, 2008, 02:17:30 AM »

Hi,
I'm using Stealth Ports Wizard to block all incoming (behind a routeur, but no trouble)

I've these firewall events, is it normal ?

Ty

Hello Xw,
Are you in The Netherlands per chance?
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #37 on: May 05, 2008, 06:33:17 AM »

Thank you salmonela, certainly.

I think that IP is an AOL proxy?

In that cause I should allow this path that was blocked then, correct?


C:\WINDOWS\system32\svchost.exe - Source IP: 172.167.102.167 - source port: 2028 - Destination IP: 205.188.146.145 - Destination port 53
Yes but long term rule for svchost.exe should be sourceIP: ANY, source port: 1025-65535 or ANY, Destination IP: Your ISP DNS servers or ANY, destination port: 53
Action: Allow
Protocol: UDP
Direction: OUT
« Last Edit: May 05, 2008, 06:38:23 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
whogivesadayyum
Newbie
*
Offline Offline

Posts: 1

Golly, another forum profile....ooooooo k.


« Reply #38 on: May 05, 2008, 09:45:33 AM »

Interesting thread.  Curious, have you noticed a "LoadPref" entry (Rsop) in your Windows Event Log?  Also, is SYSTEM on your computer using UDPTCP port 139 to LISTEN for communications and sending broadcast packets to x.x.x.255:137 or x.x.x.255:138 on your router?

I am dealing with a similiar problem, not as bad, but slightly troubling.
Logged

A great man once said, "Supersize me!"  A great undertaker said, "Thanks for the business!"
ailef
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 487



« Reply #39 on: May 05, 2008, 10:38:20 AM »

do u use some torrent client or edonkey client?
Logged

xp pro sp3 & vista ultimate sp1 (both 32bits) - comodo 3.0.25.378 - kav 8.0.0.357 - superadblocker 4.6.0.1000
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #40 on: May 05, 2008, 10:42:23 AM »

If you don't have any other PCs on your local LAN, then some services should be disabled, also UPnP and SSDP are useless noise makers (see pic)

Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
ailef
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 487



« Reply #41 on: May 05, 2008, 10:47:52 AM »

u can uncheck enable LMHOSTS too.
and snapshots are not large enough to see all the infos.
do u have some process mDNSResponder.exe working on your system?
« Last Edit: May 05, 2008, 12:01:04 PM by ailef » Logged

xp pro sp3 & vista ultimate sp1 (both 32bits) - comodo 3.0.25.378 - kav 8.0.0.357 - superadblocker 4.6.0.1000
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #42 on: May 05, 2008, 10:58:47 AM »

Yes, its from Adobe and totally useless for me

Ehh, and If running CFP and do not have any PCs who will share your Internet connection then Windows firewall service should be also disabled...
« Last Edit: May 05, 2008, 11:03:10 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo's Hero
*****
Offline Offline

Posts: 214



« Reply #43 on: May 06, 2008, 02:59:24 AM »

"Yes but long term rule for svchost.exe should be sourceIP: ANY, source port: 1025-65535 or ANY, Destination IP: Your ISP DNS servers or ANY, destination port: 53
Action: Allow
Protocol: UDP
Direction: OUT"


Interesting thing: it's now allowing that svchost.exe - it was blocking it before. I didn't change anything.



Also interesting, in my firewall alerts just now, there was an "asked" alert.

Windows Operating System - Action:asked - Protocol:IMGP - SourceIP:172.170.205.191 - DestinationIP:224.0.0.22

... never received a firewall alert asking me to do anything, never seen an "asked" alert before. 

« Last Edit: May 06, 2008, 03:12:47 AM by LirvA » Logged

"I hate myself and want to die" - Kurt Cobain
LirvA
Comodo's Hero
*****
Offline Offline

Posts: 214



« Reply #44 on: May 06, 2008, 03:02:28 AM »

"do u use some torrent client or edonkey client?"

I hop onto Tor every once in a while .... maybe once a month or so. Downloaded with the Vidalia bundle.

Firefox (FoxyProxy and Tor button add ons) - Privoxy - Tor
Logged

"I hate myself and want to die" - Kurt Cobain
Tags: firewall events 
Pages: 1 2 [3] 4 5 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.231 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com