Hi Daniel,
On Thursday 28 April 2005 2:26 pm, you wrote:
> Whenever connect via my DUN to Surfbest, the computer is constantly
> hit with .5~2K packets of UDP or TCP. The hits are constant and
> timing is from 1 to 10 minutes with most of them being less than
> every 3 minutes. Information collected by McAfee Firewall is as
> follows:
If the firewall is blocking them then it ain't good traffic !!!
> local port / Remote address / Remote port
> 67.1.135.12 (local assigned IP address by Surfbest)
> 135 / 67.1.136.86 / 1966
> 135 / 67.1.20.101 6742
> 135 / 67.1.184.208 / 2263
> 135 / 67.1.242.91 / 1859
>
> 67.1.135.0
> 445 / 84.226 196 .43 / 3441
> 135 / 67.1.178.12 / 3284
> 445 / 67.1.49.223 / 4374
> 445 / 67.1.56.152 / 3005
> 445 / 67.1.243.94 / 3592
> 135 / 67.1.118.56 / 1507
>
> 67.1.134.64
> 137 / 61.141.154.75 / 1027 / UDP
> 1026 / 61.152.158.122 / 57088 / UDP
> 1434 / 222.210.46.18 / 1135 / UDP
> 137 / 201.1.66.17 / 1028 / UDP
> 1026 / 61.235 .154 .102 / 58373 / UDP
> 1026 / 222.88.173.5 / 6062 / TCP
> 58647 / 218.61.32.43 / 80 / UDP
> 15118 / 24.65.19.226 / 3269 / TCP
> 1434 / 213.100.19.100 / 1199 / UDP
>
> Do you have any idea from where/why these hits are happening?
> Are/could they be Malious? Any information would be appreciated.
If you didn't request the packets then you can only assume that they
are malicious. If you didn't request them, then the firewall is
doing its job and blocking them.... :>)
> Daniel Wysocki
> Twin*.*Computers
> Fast Reliable Wallet-Friendly
>
--
Best Regards:
Derrick.
Pontefract Linux Users Group.
--
----------------------------------------
The WIN-HOME list is hosted on a Windows 2000(TM) machine running L-Soft
international's LISTSERV(R) software. To unsubscribe, write to
[EMAIL PROTECTED] If you have questions
about the list, write to [EMAIL PROTECTED]