Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-20-2009, 06:55 PM
RF
Guest
 
Posts: n/a
Default .....wants to send ICMP packet to your machine

Hi Experts,

I have been watching this parade of attempts to access my Win2K kernel.
Is it reasonable to assume that these are safe or? My Kerio firewall is
grabbing them by the throat every time one comes by. Great guy Kerio :-)

1 Someone on address S01060023cdc72ccb.wp.shawcable.net
[24.79.134.211] wants to send ICMP packet to your machine.

2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
[66.215.175.74] wants to send ICMP packet to your machine

3 118.173.238.87.adsl.dynamic.totbb.net
[118.173.238.87] wants to send ICMP packet to your machine

In all cases Details about Application are: tcpip kernel driver.

TIA

Reply With Quote
  #2 (permalink)  
Old 08-20-2009, 07:42 PM
1PW
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

RF wrote:
> Hi Experts,
>
> I have been watching this parade of attempts to access my Win2K kernel.
> Is it reasonable to assume that these are safe or? My Kerio firewall is
> grabbing them by the throat every time one comes by. Great guy Kerio :-)
>
> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
> [24.79.134.211] wants to send ICMP packet to your machine.
>
> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
> [66.215.175.74] wants to send ICMP packet to your machine
>
> 3 118.173.238.87.adsl.dynamic.totbb.net
> [118.173.238.87] wants to send ICMP packet to your machine
>
> In all cases Details about Application are: tcpip kernel driver.
>
> TIA


Hello RF:

It would be reasonable to assume that /none/ of these safe. Amongst
other possibles, I high probability exists that these are bots.

In addition to the notifications that your firewall yields, I hope you
are suppressing responses to these packets.

HTH

--
1PW

Reply With Quote
  #3 (permalink)  
Old 08-20-2009, 07:48 PM
Leythos
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

In article <7f5gvnF2jpak2U1@mid.individual.net>, RF@NoDen.con says...
>
> Hi Experts,
>
> I have been watching this parade of attempts to access my Win2K kernel.
> Is it reasonable to assume that these are safe or? My Kerio firewall is
> grabbing them by the throat every time one comes by. Great guy Kerio :-)
>
> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
> [24.79.134.211] wants to send ICMP packet to your machine.
>
> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
> [66.215.175.74] wants to send ICMP packet to your machine
>
> 3 118.173.238.87.adsl.dynamic.totbb.net
> [118.173.238.87] wants to send ICMP packet to your machine
>
> In all cases Details about Application are: tcpip kernel driver.
>
> TIA


Why is your computer connected directly to the Internet?

At the very least you should be sitting behind a cheap NAT router that
doesn't respond to Ping requests certainly doesn't pass anything inbound
without your permission.


--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
spam999free@rrohio.com (remove 999 for proper email address)

Reply With Quote
  #4 (permalink)  
Old 08-20-2009, 08:50 PM
Ant
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

"RF" wrote:

> I have been watching this parade of attempts to access my Win2K kernel.
> Is it reasonable to assume that these are safe or?


Could be bots scanning IP address ranges. If you're not responding to
them and don't have services configured to accept and act on
unsolicited network traffic then what's the problem?

> In all cases Details about Application are: tcpip kernel driver.


Well, it would be, since all such requests ultimately come and go
through a driver and drivers live in the kernel. It's not significant.



Reply With Quote
  #5 (permalink)  
Old 09-06-2009, 04:46 AM
RF
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

1PW wrote:
> RF wrote:
>> Hi Experts,
>>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or? My Kerio firewall is
>> grabbing them by the throat every time one comes by. Great guy Kerio :-)
>>
>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>> [24.79.134.211] wants to send ICMP packet to your machine.
>>
>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>> [66.215.175.74] wants to send ICMP packet to your machine
>>
>> 3 118.173.238.87.adsl.dynamic.totbb.net
>> [118.173.238.87] wants to send ICMP packet to your machine
>>
>> In all cases Details about Application are: tcpip kernel driver.
>>
>> TIA

>
> Hello RF:
>
> It would be reasonable to assume that /none/ of these safe. Amongst
> other possibles, I high probability exists that these are bots.
>
> In addition to the notifications that your firewall yields, I hope you
> are suppressing responses to these packets.
>
> HTH
>

Thank you 1PW. That's what I have been doing.

Reply With Quote
  #6 (permalink)  
Old 09-06-2009, 04:47 AM
RF
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

Leythos wrote:
> In article <7f5gvnF2jpak2U1@mid.individual.net>, RF@NoDen.con says...
>> Hi Experts,
>>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or? My Kerio firewall is
>> grabbing them by the throat every time one comes by. Great guy Kerio :-)
>>
>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>> [24.79.134.211] wants to send ICMP packet to your machine.
>>
>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>> [66.215.175.74] wants to send ICMP packet to your machine
>>
>> 3 118.173.238.87.adsl.dynamic.totbb.net
>> [118.173.238.87] wants to send ICMP packet to your machine
>>
>> In all cases Details about Application are: tcpip kernel driver.
>>
>> TIA


Thanks Leythos.

> Why is your computer connected directly to the Internet?


It is DSL and online while the computer is running.

> At the very least you should be sitting behind a cheap NAT router that
> doesn't respond to Ping requests certainly doesn't pass anything inbound
> without your permission.


I have a firewall.




Reply With Quote
  #7 (permalink)  
Old 09-06-2009, 05:15 AM
1PW
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

RF wrote:
> Leythos wrote:
>> In article <7f5gvnF2jpak2U1@mid.individual.net>, RF@NoDen.con says...
>>> Hi Experts,
>>>
>>> I have been watching this parade of attempts to access my Win2K kernel.
>>> Is it reasonable to assume that these are safe or? My Kerio firewall
>>> is grabbing them by the throat every time one comes by. Great guy
>>> Kerio :-)
>>>
>>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>>> [24.79.134.211] wants to send ICMP packet to your machine.
>>>
>>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>>> [66.215.175.74] wants to send ICMP packet to your machine
>>>
>>> 3 118.173.238.87.adsl.dynamic.totbb.net
>>> [118.173.238.87] wants to send ICMP packet to your machine
>>>
>>> In all cases Details about Application are: tcpip kernel driver.
>>>
>>> TIA

>
> Thanks Leythos.
>
>> Why is your computer connected directly to the Internet?

>
> It is DSL and online while the computer is running.
>
>> At the very least you should be sitting behind a cheap NAT router that
>> doesn't respond to Ping requests certainly doesn't pass anything
>> inbound without your permission.

>
> I have a firewall.


Hello RF:

Leythos' question has earned re-asking. Why are you directly
connected to the Internet? Any network device you have should only
see the LAN side of a good NAT router. Only the WLAN side of a good
NAT router should "see" your DSL modem's Ethernet port.

Well crafted malware does defeat a Kerio firewall.

--
1PW

Reply With Quote
  #8 (permalink)  
Old 09-06-2009, 05:35 AM
RF
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

Ant wrote:
> "RF" wrote:
>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or?

>
> Could be bots scanning IP address ranges. If you're not responding to
> them and don't have services configured to accept and act on
> unsolicited network traffic then what's the problem?


Programs within the computer often pop up a window (generated by the
firewall) and ask for permission to visit some other source. I often
wonder whether they are passing some info from my computer. On the other
hand the opposite is often true - they ask to have access. Usually
these requests have a name and IP# attached and, on a few ocasions I
tried to access that number and failed. I finally decided to allow the
few I can recognize the access. Strange ones get shut out.

>> In all cases Details about Application are: tcpip kernel driver.

>
> Well, it would be, since all such requests ultimately come and go
> through a driver and drivers live in the kernel. It's not significant.


The system is complicated and one can never tell what other loopholes
there are. I play it safe and minimize access. Do you know the holes and
ports that should be plugged and, if so, I'd like to know about them and
how how to block them?

Thanks for your input.

Reply With Quote
  #9 (permalink)  
Old 09-08-2009, 02:45 AM
Ant
Guest
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine

"RF" wrote:

> Programs within the computer often pop up a window (generated by the
> firewall) and ask for permission to visit some other source. I often
> wonder whether they are passing some info from my computer. On the other
> hand the opposite is often true - they ask to have access. Usually
> these requests have a name and IP# attached and, on a few ocasions I
> tried to access that number and failed. I finally decided to allow the
> few I can recognize the access. Strange ones get shut out.


Don't allow any outgoing access unless you know the software needs to
update itself and you want that to happen. However, if there is
malware on the computer it'll bypass or disable a software 'firewall'
anyway.

> Do you know the holes and ports that should be plugged and, if so,
> I'd like to know about them and how how to block them?


Since you're running W2k, you may find this helpful in shutting off
un-needed services to close ports that are listening by default:
http://www.hsc.fr/ressources/breves/...v_res_win.html



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
My new machine Ciarán Ó Duibhín alt.comp.hardware 5 12-18-2008 07:22 PM
The DVD wholesales and retails and send world www.yesverygood.com yesandgood@gmail.com uk.telecom.mobile 0 12-12-2007 04:35 PM
Pay Pal Money Machine Tony Mancuso alt.internet.wireless 0 09-09-2007 11:37 PM
Ok to let all ICMP traffic through firewall? Franklin comp.security.misc 55 09-30-2005 10:11 AM
Ok to let all ICMP traffic through firewall? Franklin alt.computer.security 47 09-26-2005 11:18 AM


All times are GMT. The time now is 02:26 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45