Hi Folks,
Not very good at understanding what the problem is that I am having. I am not sure if it is an external “attack” or just something not properly configured in one of my installed programs.
Here is an excerpt of a log file to look at (sorry it’s so much):
Date/Time :2007-02-13 18:22:01
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 169.254.1.157, Port = upnp(5000))
Protocol: UDP Incoming
Source: 169.254.1.157:5056
Destination: 169.254.1.255:upnp(5000)
Reason: Network Control Rule ID = 7
Date/Time :2007-02-13 18:22:01
Severity :High
Reporter :Network Monitor
Description: Blocked by Protocol Analysis (Fragmented IP Packet)
Direction: IP Incoming
Source: 169.254.1.75
Destination: 255.255.255.255
Protocol : UDP
Reason: Fragmented IP packets are not allowed
Date/Time :2007-02-13 18:22:00
Severity :High
Reporter :Network Monitor
Description: Blocked by Protocol Analysis (Fake or Malformed UDP Packet)
Direction: UDP Incoming
Source: 169.254.1.75:21302
Destination: 255.255.255.255:21302
Reason: UDP packet length and the size on the wire(1483 bytes) do not match
Date/Time :2007-02-13 18:21:55
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 169.254.1.75, Port = upnp(5000))
Protocol: UDP Incoming
Source: 169.254.1.75:5056
Destination: 169.254.1.255:upnp(5000)
Reason: Network Control Rule ID = 7
Date/Time :2007-02-13 18:21:55
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 169.254.1.161, Port = upnp(5000))Protocol: UDP Incoming
Source: 169.254.1.161:upnp(5000)
Destination: 169.254.1.255:upnp(5000)
Reason: Network Control Rule ID = 7
Date/Time :2007-02-13 18:21:50
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 169.254.1.157, Port = upnp(5000))Protocol: UDP Incoming
Source: 169.254.1.157:5056
Destination: 169.254.1.255:upnp(5000)
Reason: Network Control Rule ID = 7
I am not on this address scheme in my home network (169.254.X.X). Therefore, this seems like some sort of attack to me, trying to compromise UPNP. Would anyone agree with this assessment? Anything I can do to stop it?
Thanks,
rjw57