I just sent this mailing to Linksys after two, separate (frustrating!)
calls to Linksys technical support.
I thought that this might be of interest:
- - - - -
We have noticed that the newer version of the Linksys WPC11 Instant
Wireless Configuration Utility that comes bundled with the Linksys
drivers sends packets to various Internet IP addresses via TCP Port 13 -
[ Daytime ]. This aforementioned suspicious packet activity can be
replicated and viewed quite easily using a Windows 2000 or Windows XP
computer:
-1- Download and install the latest WPC11 version 3 drivers from the
Linksys FTP site:
ftp://ftp.linksys.com/pub/network/wp...ity_053003.exe
-2- Download and install TCPView from the following Website:
http://www.sysinternals.com/ntw2k/source/tcpview.shtml
-3- Start TCPView.
-4- Start the Linksys Wireless Configuration Utility version 1.5 and
configure the WPC11 version 3. Almost immediately, packets will be sent
to various Internet IP Addresses via TCP Port 13 and the suspicious Port
13 activity will appear in the TCPView listing of current network
activity.
-5- Exiting out of the Instant Wireless Configuration Utility will
immediately suspend the suspicious Port 13 activity.
Listed below is a SMALL sampling of the suspicious TCP Port 13 activity
as captured by our firewall logfiles:
- - - - - B E G I N F I R E W A L L L O G - - - - -
Sending TCP Reset as port (13) not allowed. Original packet
(192.168.10.185->81.52.249.54: Protocol=TCP[SYN] Port 1028->13) received
on interface 192.168.10.83
Sending TCP Reset as port (13) not allowed. Original packet
(192.168.10.185->209.246.46.51: Protocol=TCP[SYN] Port 1028->13) received
on interface 192.168.10.83
Sending TCP Reset as port (13) not allowed. Original packet
(192.168.10.185->81.52.249.71: Protocol=TCP[SYN] Port 1028->13) received
on interface 192.168.10.83
Sending TCP Reset as port (13) not allowed. Original packet
(192.168.10.185->81.52.249.95: Protocol=TCP[SYN] Port 1028->13) received
on interface 192.168.10.83
- - - - - E N D F I R E W A L L L O G - - - - -
This aforementioned behavior is also seen using version 1.4 of the
Instant Wireless Configuration Utility for the WPC11 version 3.
- - - - -
meatjamesgracedotcom