Welcome, Guest. Please login or register.
July 24, 2008, 05:22:35 PM

Login with username, password and session length

176789 Posts
20900 Topics
50701 Members

Latest Member: toze

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  What are these firewall events? (screenshots)
« previous next »
Pages: 1 [2] 3 4 5 Go Down Print
Author Topic: What are these firewall events? (screenshots)  (Read 3567 times)
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #15 on: May 04, 2008, 11:48:04 PM »

"Do you have any outbound requests active now?"

no, dont think so. You would check that in "view active connections" right?
Yes you are right, maybe you should put log on outgoing rules, to maybe see if something "calling" those blocked inbound...
« Last Edit: May 04, 2008, 11:49:37 PM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #16 on: May 04, 2008, 11:55:11 PM »

Well it shows I have some legitimate processes listening .... 

Are these applications being denied legitimate access?




"maybe you should put log on outgoing rules"

how do I do that please?
Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #17 on: May 05, 2008, 12:05:02 AM »

Edit your first global rule (where all output connection are allowed) like arrow suggested and nothing else (see pic)
« Last Edit: May 05, 2008, 12:07:03 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #18 on: May 05, 2008, 12:16:14 AM »

I change to this (screenshot) and it prevented any internet connection. I undid the change.

What did I do wrong?

I now am back to original settings (2nd screenshot)
Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #19 on: May 05, 2008, 12:16:37 AM »

EDIT:
ONLY tick log as firewall event if this rule is fired, other things leave intact on your original 2nd screenshot

...Then you should see all established connection in CFP "firewall events"...
« Last Edit: May 05, 2008, 12:27:41 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #20 on: May 05, 2008, 12:29:25 AM »

Oh, ONLY CHANGE the "log as firewall even if fired" (screenshot)

Resulting in (2nd screenshot)

Is this correct?
Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #21 on: May 05, 2008, 12:33:52 AM »

Yes Smiley
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #22 on: May 05, 2008, 12:37:34 AM »

Now Firewall events shows (3 screen shots)

(first 2 in this post)
Logged

"I hate myself and want to die" - Kurt Cobain
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #23 on: May 05, 2008, 12:39:49 AM »

(3rd screenshot)

All screenshots combine to show all firewall events.
Logged

"I hate myself and want to die" - Kurt Cobain
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #24 on: May 05, 2008, 12:44:02 AM »

Ahh. Thank you very very much. Much appreciated.

What will be the result of this edit? Will this lower the firewall events? Anything beneficial?


Also, in 3rd screenshot (after edit) it shows some things blocked, just like in my original screenshot (following screenshot)

Are these events like port scans or ping attacks or something?

Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #25 on: May 05, 2008, 12:56:51 AM »

Do you know what are your internet providers DNS servers?
On third screen you have blocked (cant see, is it svchost.exe?) on Domain Name Server port 53 on remote 205.188.146.Huh
If this is true and your DNS IP is 205.188.146.Huh (cant see last number) then you should enable it...
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #26 on: May 05, 2008, 01:02:49 AM »

 what are you have in "your network zone"? (firewall -  common task - My network zones)
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #27 on: May 05, 2008, 01:15:57 AM »

"Do you know what are your internet providers DNS servers?"

No, but I can possibly find out if I need to. ......




"On third screen you have blocked (cant see, is it svchost.exe?) on Domain Name Server port 53 on remote 205.188.146."


Yes, the path is as follows:

C:\WINDOWS\system32\svchost.exe - Source IP: 172.167.102.167 -
source port: 2028 - Destination IP: 205.188.146.145 - Destination port 53


"If this is true and your DNS IP is 205.188.146.Huh (cant see last number) then you should enable it"

I need to allow this then? Do I need to contact my ISP (AOL) real quick?



"what are you have in "your network zone"? (firewall -  common task - My network zones)"


One moment, I'll fetch a screenshot.
Logged

"I hate myself and want to die" - Kurt Cobain
LirvA
Comodo Loves me
****
Offline Offline

Posts: 172



« Reply #28 on: May 05, 2008, 01:19:50 AM »

My Network Zones ....
Logged

"I hate myself and want to die" - Kurt Cobain
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #29 on: May 05, 2008, 01:31:20 AM »

Ahh. Thank you very very much. Much appreciated.

What will be the result of this edit? Will this lower the firewall events? Anything beneficial?

You now see more firewall events
Quote
Are these events like port scans or ping attacks or something? 

your first picture on this tread is "fishy"




« Last Edit: May 05, 2008, 01:36:04 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Tags: firewall events 
Pages: 1 [2] 3 4 5 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.099 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com