Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - .....wants to send ICMP packet to your machine

 
Thread Tools Search this Thread
Old 08-20-2009, 06:55 PM   #1
Default .....wants to send ICMP packet to your machine


Hi Experts,

I have been watching this parade of attempts to access my Win2K kernel.
Is it reasonable to assume that these are safe or? My Kerio firewall is
grabbing them by the throat every time one comes by. Great guy Kerio

1 Someone on address S01060023cdc72ccb.wp.shawcable.net
[24.79.134.211] wants to send ICMP packet to your machine.

2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
[66.215.175.74] wants to send ICMP packet to your machine

3 118.173.238.87.adsl.dynamic.totbb.net
[118.173.238.87] wants to send ICMP packet to your machine

In all cases Details about Application are: tcpip kernel driver.

TIA


RF
  Reply With Quote
Old 08-20-2009, 07:42 PM   #2
1PW
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
RF wrote:
> Hi Experts,
>
> I have been watching this parade of attempts to access my Win2K kernel.
> Is it reasonable to assume that these are safe or? My Kerio firewall is
> grabbing them by the throat every time one comes by. Great guy Kerio
>
> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
> [24.79.134.211] wants to send ICMP packet to your machine.
>
> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
> [66.215.175.74] wants to send ICMP packet to your machine
>
> 3 118.173.238.87.adsl.dynamic.totbb.net
> [118.173.238.87] wants to send ICMP packet to your machine
>
> In all cases Details about Application are: tcpip kernel driver.
>
> TIA


Hello RF:

It would be reasonable to assume that /none/ of these safe. Amongst
other possibles, I high probability exists that these are bots.

In addition to the notifications that your firewall yields, I hope you
are suppressing responses to these packets.

HTH

--
1PW


1PW
  Reply With Quote
Old 08-20-2009, 07:48 PM   #3
Leythos
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
In article <>, says...
>
> Hi Experts,
>
> I have been watching this parade of attempts to access my Win2K kernel.
> Is it reasonable to assume that these are safe or? My Kerio firewall is
> grabbing them by the throat every time one comes by. Great guy Kerio
>
> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
> [24.79.134.211] wants to send ICMP packet to your machine.
>
> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
> [66.215.175.74] wants to send ICMP packet to your machine
>
> 3 118.173.238.87.adsl.dynamic.totbb.net
> [118.173.238.87] wants to send ICMP packet to your machine
>
> In all cases Details about Application are: tcpip kernel driver.
>
> TIA


Why is your computer connected directly to the Internet?

At the very least you should be sitting behind a cheap NAT router that
doesn't respond to Ping requests certainly doesn't pass anything inbound
without your permission.


--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
(remove 999 for proper email address)


Leythos
  Reply With Quote
Old 09-06-2009, 04:46 AM   #4
RF
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
1PW wrote:
> RF wrote:
>> Hi Experts,
>>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or? My Kerio firewall is
>> grabbing them by the throat every time one comes by. Great guy Kerio
>>
>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>> [24.79.134.211] wants to send ICMP packet to your machine.
>>
>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>> [66.215.175.74] wants to send ICMP packet to your machine
>>
>> 3 118.173.238.87.adsl.dynamic.totbb.net
>> [118.173.238.87] wants to send ICMP packet to your machine
>>
>> In all cases Details about Application are: tcpip kernel driver.
>>
>> TIA

>
> Hello RF:
>
> It would be reasonable to assume that /none/ of these safe. Amongst
> other possibles, I high probability exists that these are bots.
>
> In addition to the notifications that your firewall yields, I hope you
> are suppressing responses to these packets.
>
> HTH
>

Thank you 1PW. That's what I have been doing.


RF
  Reply With Quote
Old 09-06-2009, 04:47 AM   #5
RF
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
Leythos wrote:
> In article <>, says...
>> Hi Experts,
>>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or? My Kerio firewall is
>> grabbing them by the throat every time one comes by. Great guy Kerio
>>
>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>> [24.79.134.211] wants to send ICMP packet to your machine.
>>
>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>> [66.215.175.74] wants to send ICMP packet to your machine
>>
>> 3 118.173.238.87.adsl.dynamic.totbb.net
>> [118.173.238.87] wants to send ICMP packet to your machine
>>
>> In all cases Details about Application are: tcpip kernel driver.
>>
>> TIA


Thanks Leythos.

> Why is your computer connected directly to the Internet?


It is DSL and online while the computer is running.

> At the very least you should be sitting behind a cheap NAT router that
> doesn't respond to Ping requests certainly doesn't pass anything inbound
> without your permission.


I have a firewall.





RF
  Reply With Quote
Old 09-06-2009, 05:15 AM   #6
1PW
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
RF wrote:
> Leythos wrote:
>> In article <>, says...
>>> Hi Experts,
>>>
>>> I have been watching this parade of attempts to access my Win2K kernel.
>>> Is it reasonable to assume that these are safe or? My Kerio firewall
>>> is grabbing them by the throat every time one comes by. Great guy
>>> Kerio
>>>
>>> 1 Someone on address S01060023cdc72ccb.wp.shawcable.net
>>> [24.79.134.211] wants to send ICMP packet to your machine.
>>>
>>> 2 Someone on address 66-215-175-74.dhcp.snbr.ca.charter.com
>>> [66.215.175.74] wants to send ICMP packet to your machine
>>>
>>> 3 118.173.238.87.adsl.dynamic.totbb.net
>>> [118.173.238.87] wants to send ICMP packet to your machine
>>>
>>> In all cases Details about Application are: tcpip kernel driver.
>>>
>>> TIA

>
> Thanks Leythos.
>
>> Why is your computer connected directly to the Internet?

>
> It is DSL and online while the computer is running.
>
>> At the very least you should be sitting behind a cheap NAT router that
>> doesn't respond to Ping requests certainly doesn't pass anything
>> inbound without your permission.

>
> I have a firewall.


Hello RF:

Leythos' question has earned re-asking. Why are you directly
connected to the Internet? Any network device you have should only
see the LAN side of a good NAT router. Only the WLAN side of a good
NAT router should "see" your DSL modem's Ethernet port.

Well crafted malware does defeat a Kerio firewall.

--
1PW


1PW
  Reply With Quote
Old 09-06-2009, 05:35 AM   #7
RF
 
Posts: n/a
Default Re: .....wants to send ICMP packet to your machine
Ant wrote:
> "RF" wrote:
>
>> I have been watching this parade of attempts to access my Win2K kernel.
>> Is it reasonable to assume that these are safe or?

>
> Could be bots scanning IP address ranges. If you're not responding to
> them and don't have services configured to accept and act on
> unsolicited network traffic then what's the problem?


Programs within the computer often pop up a window (generated by the
firewall) and ask for permission to visit some other source. I often
wonder whether they are passing some info from my computer. On the other
hand the opposite is often true - they ask to have access. Usually
these requests have a name and IP# attached and, on a few ocasions I
tried to access that number and failed. I finally decided to allow the
few I can recognize the access. Strange ones get shut out.

>> In all cases Details about Application are: tcpip kernel driver.

>
> Well, it would be, since all such requests ultimately come and go
> through a driver and drivers live in the kernel. It's not significant.


The system is complicated and one can never tell what other loopholes
there are. I play it safe and minimize access. Do you know the holes and
ports that should be plugged and, if so, I'd like to know about them and
how how to block them?

Thanks for your input.


RF
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
pcAnywhere and Brother fax machine on same phoen line bem522 Software 0 07-20-2007 04:20 PM
IMHO, Digital SECAM video is better than Analog NTSC video Radium DVD Video 167 10-25-2006 04:16 AM
Re: Can't login to XP Pro machine jjw A+ Certification 2 10-19-2004 12:36 AM
Re: Can't login to XP Pro machine Solomon Kozanski A+ Certification 5 09-25-2004 05:24 PM
Re: Can't login to XP Pro machine Gary A+ Certification 3 09-22-2004 10:17 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46