Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Unknown Connection

 
Thread Tools Search this Thread
Old 03-20-2007, 10:04 PM   #1
Default Unknown Connection


Router WRT54G Linksys (with DD-WRT Firmware)

In my syslog i have following:

8 12:03:44 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18 12:03:44 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18 12:03:43 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18 12:03:43 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18 12:03:34 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18 12:03:34 I udp 10.34.107.25 67 255.255.255.255 68
2007/03/18

I had this connection with Hyperwrt too!
Always denied and Service "bootpc" it was mentioned ...

ping and tracert to the ip is not possible, it times out ...

IP is a private one, so ripe unuseful ...

Is this another router?

Following to port it is:

68/tcp bootpc Bootstrap Protocol Client
68/udp bootpc Bootstrap Protocol Client

Connected is only one pc and sometimes my notebook ... (pc mostly
turned off then)


Andreas Rainer
  Reply With Quote
Old 03-20-2007, 10:33 PM   #2
David H. Lipman
 
Posts: n/a
Default Re: Unknown Connection
From: "Andreas Rainer" <>

| Router WRT54G Linksys (with DD-WRT Firmware)
|
| In my syslog i have following:
|
| 8 12:03:44 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18 12:03:44 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18 12:03:43 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18 12:03:43 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18 12:03:34 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18 12:03:34 I udp 10.34.107.25 67 255.255.255.255 68
| 2007/03/18
|
| I had this connection with Hyperwrt too!
| Always denied and Service "bootpc" it was mentioned ...
|
| ping and tracert to the ip is not possible, it times out ...
|
| IP is a private one, so ripe unuseful ...
|
| Is this another router?
|
| Following to port it is:
|
| 68/tcp bootpc Bootstrap Protocol Client
| 68/udp bootpc Bootstrap Protocol Client
|
| Connected is only one pc and sometimes my notebook ... (pc mostly
| turned off then)

There is no security aspect here. This is just a BootP request on a local, non-routable,
sub-net.

Futher queries should be made in a TCP/IP related News Group to understand Private Addresses
and the BootP Protocol.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 03-20-2007, 10:41 PM   #3
Andreas Rainer
 
Posts: n/a
Default Re: Unknown Connection
On Tue, 20 Mar 2007 22:33:50 GMT, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

>| Connected is only one pc and sometimes my notebook ... (pc mostly
>| turned off then)
>
>There is no security aspect here. This is just a BootP request on a local, non-routable,
>sub-net.

So it can't be a wireless hacker?
My Router has local and wireless LAN connection ...
internal IPs start with 192.168. ....
that's why i was wondering ...
>
>Futher queries should be made in a TCP/IP related News Group to understand Private Addresses
>and the BootP Protocol.

which group do you suggest?


Andreas Rainer
  Reply With Quote
Old 03-20-2007, 10:58 PM   #4
David H. Lipman
 
Posts: n/a
Default Re: Unknown Connection
From: "Andreas Rainer" <>


| So it can't be a wireless hacker?
| My Router has local and wireless LAN connection ...
| internal IPs start with 192.168. ....
| that's why i was wondering ...

If you are using wireless then it may be a remote platform trying to obtain an IP from the
Router. Since it is the WRONG network, it will go nowhwere.

TCP/UDP port 67 & 68 are used BootP/BootPS hich is the older way of obtainuing an IP address
which was replaced with DHCP.

If you want to increase wireless security, make sure that the Router will only assign
addresses to provided MAC addresses.


>>
>> Futher queries should be made in a TCP/IP related News Group to understand Private
>> Addresses and the BootP Protocol.

| which group do you suggest?

news:comp.protocols.tcp-ip



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 03-21-2007, 01:24 AM   #5
Sebastian Gottschalk
 
Posts: n/a
Default Re: Unknown Connection
David H. Lipman wrote:

> From: "Andreas Rainer" <>
>
>| So it can't be a wireless hacker?
>| My Router has local and wireless LAN connection ...
>| internal IPs start with 192.168. ....
>| that's why i was wondering ...
>
> If you are using wireless then it may be a remote platform trying to obtain an IP from the
> Router. Since it is the WRONG network, it will go nowhwere.
>
> TCP/UDP port 67 & 68 are used BootP/BootPS hich is the older way of obtainuing an IP address
> which was replaced with DHCP.


Ehm... this *is* DHCP.

> If you want to increase wireless security, make sure that the Router will only assign
> addresses to provided MAC addresses.


The increase in security is *zero*.


Sebastian Gottschalk
  Reply With Quote
Old 03-21-2007, 06:00 PM   #6
Andreas Rainer
 
Posts: n/a
Default Re: Unknown Connection
On Wed, 21 Mar 2007 02:24:46 +0100, Sebastian Gottschalk
<> wrote:

>> TCP/UDP port 67 & 68 are used BootP/BootPS hich is the older way of obtainuing an IP address
>> which was replaced with DHCP.

>
>Ehm... this *is* DHCP.

I know that it is
The question where does it come from?
I only see the Wireless Networks (about 7 Routers and 2 Laptops seen),
but it seems strange to me, that i see an IP in my denied Log ...

My LAN IP starts with 192.168
Provider IP with 80.109 ...

So i am wondering from where the IP is ...
Wireless or Provider?
Tracert/ping are not possible

Thats why i thought maybe security thing
>
>> If you want to increase wireless security, make sure that the Router will only assign
>> addresses to provided MAC addresses.

>
>The increase in security is *zero*.

WPE 128 + Mac only assigned is set

Is it still possible to come a network, if both are set?


Andreas Rainer
  Reply With Quote
Old 03-21-2007, 10:38 PM   #7
Sebastian Gottschalk
 
Posts: n/a
Default Re: Unknown Connection
Andreas Rainer wrote:

> On Wed, 21 Mar 2007 02:24:46 +0100, Sebastian Gottschalk
> <> wrote:
>
>>> TCP/UDP port 67 & 68 are used BootP/BootPS hich is the older way of obtainuing an IP address
>>> which was replaced with DHCP.

>>
>>Ehm... this *is* DHCP.

> I know that it is
> The question where does it come from?
> I only see the Wireless Networks (about 7 Routers and 2 Laptops seen),


Since Wireless is an option, it could about anybody...

> WPE 128 + Mac only assigned is set
>
> Is it still possible to come a network, if both are set?


Cracking WEP-128 takes about 5 minutes on average. Cloning the MAC address
from legitimate packet flying around takes about 5 milliseconds.


Sebastian Gottschalk
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Losing internet connection after 5 mins? Alexgtbeetle General Help Related Topics 0 09-03-2008 03:15 PM
Loses Internet Connection jmoore00 General Help Related Topics 0 09-24-2007 05:23 AM
How to configure VPN hi5 Hardware 1 07-09-2007 12:21 PM
Spurious Internet Connection ch742718 Hardware 5 07-19-2006 07:12 AM
Laptop wireless connection johnnygeargrinder2004@yahoo.com A+ Certification 7 03-09-2005 03:05 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46