![]() |
|
|
|||||||
![]() |
Computer Security - .....wants to send ICMP packet to your machine |
|
|
Thread Tools | Search this Thread |
|
|
#1 |
|
Hi Experts,
I have been watching this parade of attempts to access my Win2K kernel. Is it reasonable to assume that these are safe or? My Kerio firewall is grabbing them by the throat every time one comes by. Great guy Kerio 1 Someone on address S01060023cdc72ccb.wp.shawcable.net [24.79.134.211] wants to send ICMP packet to your machine. 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com [66.215.175.74] wants to send ICMP packet to your machine 3 118.173.238.87.adsl.dynamic.totbb.net [118.173.238.87] wants to send ICMP packet to your machine In all cases Details about Application are: tcpip kernel driver. TIA RF |
|
|
|
|
#2 |
|
Posts: n/a
|
RF wrote:
> Hi Experts, > > I have been watching this parade of attempts to access my Win2K kernel. > Is it reasonable to assume that these are safe or? My Kerio firewall is > grabbing them by the throat every time one comes by. Great guy Kerio > > 1 Someone on address S01060023cdc72ccb.wp.shawcable.net > [24.79.134.211] wants to send ICMP packet to your machine. > > 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com > [66.215.175.74] wants to send ICMP packet to your machine > > 3 118.173.238.87.adsl.dynamic.totbb.net > [118.173.238.87] wants to send ICMP packet to your machine > > In all cases Details about Application are: tcpip kernel driver. > > TIA Hello RF: It would be reasonable to assume that /none/ of these safe. Amongst other possibles, I high probability exists that these are bots. In addition to the notifications that your firewall yields, I hope you are suppressing responses to these packets. HTH -- 1PW 1PW |
|
|
|
#3 |
|
Posts: n/a
|
In article <>, says...
> > Hi Experts, > > I have been watching this parade of attempts to access my Win2K kernel. > Is it reasonable to assume that these are safe or? My Kerio firewall is > grabbing them by the throat every time one comes by. Great guy Kerio > > 1 Someone on address S01060023cdc72ccb.wp.shawcable.net > [24.79.134.211] wants to send ICMP packet to your machine. > > 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com > [66.215.175.74] wants to send ICMP packet to your machine > > 3 118.173.238.87.adsl.dynamic.totbb.net > [118.173.238.87] wants to send ICMP packet to your machine > > In all cases Details about Application are: tcpip kernel driver. > > TIA Why is your computer connected directly to the Internet? At the very least you should be sitting behind a cheap NAT router that doesn't respond to Ping requests certainly doesn't pass anything inbound without your permission. -- You can't trust your best friends, your five senses, only the little voice inside you that most civilians don't even hear -- Listen to that. Trust yourself. (remove 999 for proper email address) Leythos |
|
|
|
#4 |
|
Posts: n/a
|
1PW wrote:
> RF wrote: >> Hi Experts, >> >> I have been watching this parade of attempts to access my Win2K kernel. >> Is it reasonable to assume that these are safe or? My Kerio firewall is >> grabbing them by the throat every time one comes by. Great guy Kerio >> >> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net >> [24.79.134.211] wants to send ICMP packet to your machine. >> >> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com >> [66.215.175.74] wants to send ICMP packet to your machine >> >> 3 118.173.238.87.adsl.dynamic.totbb.net >> [118.173.238.87] wants to send ICMP packet to your machine >> >> In all cases Details about Application are: tcpip kernel driver. >> >> TIA > > Hello RF: > > It would be reasonable to assume that /none/ of these safe. Amongst > other possibles, I high probability exists that these are bots. > > In addition to the notifications that your firewall yields, I hope you > are suppressing responses to these packets. > > HTH > Thank you 1PW. That's what I have been doing. RF |
|
|
|
#5 |
|
Posts: n/a
|
Leythos wrote:
> In article <>, says... >> Hi Experts, >> >> I have been watching this parade of attempts to access my Win2K kernel. >> Is it reasonable to assume that these are safe or? My Kerio firewall is >> grabbing them by the throat every time one comes by. Great guy Kerio >> >> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net >> [24.79.134.211] wants to send ICMP packet to your machine. >> >> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com >> [66.215.175.74] wants to send ICMP packet to your machine >> >> 3 118.173.238.87.adsl.dynamic.totbb.net >> [118.173.238.87] wants to send ICMP packet to your machine >> >> In all cases Details about Application are: tcpip kernel driver. >> >> TIA Thanks Leythos. > Why is your computer connected directly to the Internet? It is DSL and online while the computer is running. > At the very least you should be sitting behind a cheap NAT router that > doesn't respond to Ping requests certainly doesn't pass anything inbound > without your permission. I have a firewall. RF |
|
|
|
#6 |
|
Posts: n/a
|
RF wrote:
> Leythos wrote: >> In article <>, says... >>> Hi Experts, >>> >>> I have been watching this parade of attempts to access my Win2K kernel. >>> Is it reasonable to assume that these are safe or? My Kerio firewall >>> is grabbing them by the throat every time one comes by. Great guy >>> Kerio >>> >>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net >>> [24.79.134.211] wants to send ICMP packet to your machine. >>> >>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com >>> [66.215.175.74] wants to send ICMP packet to your machine >>> >>> 3 118.173.238.87.adsl.dynamic.totbb.net >>> [118.173.238.87] wants to send ICMP packet to your machine >>> >>> In all cases Details about Application are: tcpip kernel driver. >>> >>> TIA > > Thanks Leythos. > >> Why is your computer connected directly to the Internet? > > It is DSL and online while the computer is running. > >> At the very least you should be sitting behind a cheap NAT router that >> doesn't respond to Ping requests certainly doesn't pass anything >> inbound without your permission. > > I have a firewall. Hello RF: Leythos' question has earned re-asking. Why are you directly connected to the Internet? Any network device you have should only see the LAN side of a good NAT router. Only the WLAN side of a good NAT router should "see" your DSL modem's Ethernet port. Well crafted malware does defeat a Kerio firewall. -- 1PW 1PW |
|
|
|
#7 |
|
Posts: n/a
|
Ant wrote:
> "RF" wrote: > >> I have been watching this parade of attempts to access my Win2K kernel. >> Is it reasonable to assume that these are safe or? > > Could be bots scanning IP address ranges. If you're not responding to > them and don't have services configured to accept and act on > unsolicited network traffic then what's the problem? Programs within the computer often pop up a window (generated by the firewall) and ask for permission to visit some other source. I often wonder whether they are passing some info from my computer. On the other hand the opposite is often true - they ask to have access. Usually these requests have a name and IP# attached and, on a few ocasions I tried to access that number and failed. I finally decided to allow the few I can recognize the access. Strange ones get shut out. >> In all cases Details about Application are: tcpip kernel driver. > > Well, it would be, since all such requests ultimately come and go > through a driver and drivers live in the kernel. It's not significant. The system is complicated and one can never tell what other loopholes there are. I play it safe and minimize access. Do you know the holes and ports that should be plugged and, if so, I'd like to know about them and how how to block them? Thanks for your input. RF |
|
![]() |
| Thread Tools | Search this Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| pcAnywhere and Brother fax machine on same phoen line | bem522 | Software | 0 | 07-20-2007 04:20 PM |
| IMHO, Digital SECAM video is better than Analog NTSC video | Radium | DVD Video | 167 | 10-25-2006 04:16 AM |
| Re: Can't login to XP Pro machine | jjw | A+ Certification | 2 | 10-19-2004 12:36 AM |
| Re: Can't login to XP Pro machine | Solomon Kozanski | A+ Certification | 5 | 09-25-2004 05:24 PM |
| Re: Can't login to XP Pro machine | Gary | A+ Certification | 3 | 09-22-2004 10:17 PM |