Networking Forums

Networking Forums > Computer Networking > Windows Networking > repeated connection attempts blocked by firewall

Reply
Thread Tools Display Modes

repeated connection attempts blocked by firewall

 
 
George Valkov
Guest
Posts: n/a

 
      05-26-2007, 09:17 AM
Hello!
I woke up this morning, started my DSL modem (takes new IP from DHCP), and
started my PC (behind hardware firewall). I noticed a lot of in-bound
traffic filtered by the firewall.
And so, I checked the firewall log file:
http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
and noticed that a few hosts are trying to access some service - mostly
TCP:12824 that is filtered by the firewall. Being filtered means that they
cannot determine if there is a host, unless they send a PING for it.

My question is:
is the client software that stupid to repeat connection every quarter of a
second?
or is that some attack against the previous owner of that IP?
or is that some Trojan client trying to access server on previous owner of
that IP?
or why is that behaviour?
It makes no sense repeating the connection attempt that frequently, unless
trying to flood the other side. Which also does not make sense because this
IP is being assigned to clients of the ISP and not to a server, and flood
attacks are usually used to prevent access to a specific server.

My action was to reset the DSL modem again and take a new "clean" IP for the
DSL modem.

I am also going to ask my ISP to configure the modem not to respond to ICMP
packets.



Thank you for any information and shared knowledge!

George Valkov


 
Reply With Quote
 
 
 
 
Jack \(MVP-Networking\).
Guest
Posts: n/a

 
      05-26-2007, 03:49 PM
Hi
If you are referring to traffic trying to come in, it is probably regular
Internet and ISP noise and as long as it does not impede your connection it
can be ignored.
Jack (MVP-Networking).

"George Valkov" <(E-Mail Removed)> wrote in message
news:emPt%(E-Mail Removed)...
> Hello!
> I woke up this morning, started my DSL modem (takes new IP from DHCP), and
> started my PC (behind hardware firewall). I noticed a lot of in-bound
> traffic filtered by the firewall.
> And so, I checked the firewall log file:
> http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
> and noticed that a few hosts are trying to access some service - mostly
> TCP:12824 that is filtered by the firewall. Being filtered means that they
> cannot determine if there is a host, unless they send a PING for it.
>
> My question is:
> is the client software that stupid to repeat connection every quarter of a
> second?
> or is that some attack against the previous owner of that IP?
> or is that some Trojan client trying to access server on previous owner of
> that IP?
> or why is that behaviour?
> It makes no sense repeating the connection attempt that frequently, unless
> trying to flood the other side. Which also does not make sense because
> this
> IP is being assigned to clients of the ISP and not to a server, and flood
> attacks are usually used to prevent access to a specific server.
>
> My action was to reset the DSL modem again and take a new "clean" IP for
> the
> DSL modem.
>
> I am also going to ask my ISP to configure the modem not to respond to
> ICMP
> packets.
>
>
>
> Thank you for any information and shared knowledge!
>
> George Valkov
>
>



 
Reply With Quote
 
George Valkov
Guest
Posts: n/a

 
      05-26-2007, 04:06 PM
Yes it is and since my PC is firewalled id can be ignorred, except the part
thet it fills the firewall's entire log-file pretty fast. Resetting the DSL
modem to take a new IP as also an easy game...

Next time I'll let it go into the Network protocol analyzer, to see what's
iside :-)



"Jack (MVP-Networking)." wrote:
| Hi
| If you are referring to traffic trying to come in, it is probably regular
| Internet and ISP noise and as long as it does not impede your connection
it
| can be ignored.
| Jack (MVP-Networking).
|
| "George Valkov" <(E-Mail Removed)> wrote in message
| news:emPt%(E-Mail Removed)...
| > Hello!
| > I woke up this morning, started my DSL modem (takes new IP from DHCP),
and
| > started my PC (behind hardware firewall). I noticed a lot of in-bound
| > traffic filtered by the firewall.
| > And so, I checked the firewall log file:
| > http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
| > and noticed that a few hosts are trying to access some service - mostly
| > TCP:12824 that is filtered by the firewall. Being filtered means that
they
| > cannot determine if there is a host, unless they send a PING for it.
| >
| > My question is:
| > is the client software that stupid to repeat connection every quarter of
a
| > second?
| > or is that some attack against the previous owner of that IP?
| > or is that some Trojan client trying to access server on previous owner
of
| > that IP?
| > or why is that behaviour?
| > It makes no sense repeating the connection attempt that frequently,
unless
| > trying to flood the other side. Which also does not make sense because
| > this
| > IP is being assigned to clients of the ISP and not to a server, and
flood
| > attacks are usually used to prevent access to a specific server.
| >
| > My action was to reset the DSL modem again and take a new "clean" IP for
| > the
| > DSL modem.
| >
| > I am also going to ask my ISP to configure the modem not to respond to
| > ICMP
| > packets.
| >
| >
| >
| > Thank you for any information and shared knowledge!
| >
| > George Valkov
| >
| >
|
|


 
Reply With Quote
 
George Valkov
Guest
Posts: n/a

 
      05-26-2007, 04:10 PM
I'll let it talk to a netcat server, just to make it even more realistic ;-)

"Jack (MVP-Networking)." wrote:
| Hi
| If you are referring to traffic trying to come in, it is probably regular
| Internet and ISP noise and as long as it does not impede your connection
it
| can be ignored.
| Jack (MVP-Networking).
|
| "George Valkov" <(E-Mail Removed)> wrote in message
| news:emPt%(E-Mail Removed)...
| > Hello!
| > I woke up this morning, started my DSL modem (takes new IP from DHCP),
and
| > started my PC (behind hardware firewall). I noticed a lot of in-bound
| > traffic filtered by the firewall.
| > And so, I checked the firewall log file:
| > http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
| > and noticed that a few hosts are trying to access some service - mostly
| > TCP:12824 that is filtered by the firewall. Being filtered means that
they
| > cannot determine if there is a host, unless they send a PING for it.
| >
| > My question is:
| > is the client software that stupid to repeat connection every quarter of
a
| > second?
| > or is that some attack against the previous owner of that IP?
| > or is that some Trojan client trying to access server on previous owner
of
| > that IP?
| > or why is that behaviour?
| > It makes no sense repeating the connection attempt that frequently,
unless
| > trying to flood the other side. Which also does not make sense because
| > this
| > IP is being assigned to clients of the ISP and not to a server, and
flood
| > attacks are usually used to prevent access to a specific server.
| >
| > My action was to reset the DSL modem again and take a new "clean" IP for
| > the
| > DSL modem.
| >
| > I am also going to ask my ISP to configure the modem not to respond to
| > ICMP
| > packets.
| >
| >
| >
| > Thank you for any information and shared knowledge!
| >
| > George Valkov
| >
| >
|
|


 
Reply With Quote
 
Chuck
Guest
Posts: n/a

 
      05-26-2007, 04:16 PM
On Sat, 26 May 2007 12:17:52 +0300, "George Valkov" <(E-Mail Removed)> wrote:

>Hello!
>I woke up this morning, started my DSL modem (takes new IP from DHCP), and
>started my PC (behind hardware firewall). I noticed a lot of in-bound
>traffic filtered by the firewall.
>And so, I checked the firewall log file:
>http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
>and noticed that a few hosts are trying to access some service - mostly
>TCP:12824 that is filtered by the firewall. Being filtered means that they
>cannot determine if there is a host, unless they send a PING for it.
>
>My question is:
>is the client software that stupid to repeat connection every quarter of a
>second?
>or is that some attack against the previous owner of that IP?
>or is that some Trojan client trying to access server on previous owner of
>that IP?
>or why is that behaviour?
>It makes no sense repeating the connection attempt that frequently, unless
>trying to flood the other side. Which also does not make sense because this
>IP is being assigned to clients of the ISP and not to a server, and flood
>attacks are usually used to prevent access to a specific server.
>
>My action was to reset the DSL modem again and take a new "clean" IP for the
>DSL modem.
>
>I am also going to ask my ISP to configure the modem not to respond to ICMP
>packets.
>
>
>
>Thank you for any information and shared knowledge!
>
>George Valkov
>


George,

Whenever I see an access attempted against a specific port, I look it up in the
ISC / SANS database.
http://isc.sans.org/port.html?port=12824

That shows 2 things:
1) There is an increasing amount of traffic against that port, being reported.
2) Nobody knows what it is (If an attack port is known it will be identified
here, if anywhere).

Bottom line is, you aren't alone. Watch the ISC page for updates.

--
Cheers,
Chuck, MS-MVP [Windows - Networking]
http://nitecruzr.blogspot.com/
Paranoia is not a problem, when it's a normal response from experience.
My email is AT DOT
actual address pchuck mvps org.
 
Reply With Quote
 
George Valkov
Guest
Posts: n/a

 
      05-26-2007, 04:38 PM

"Chuck" wrote:
| On Sat, 26 May 2007 12:17:52 +0300, "George Valkov" <(E-Mail Removed)> wrote:
|
| >Hello!
| >I woke up this morning, started my DSL modem (takes new IP from DHCP),
and
| >started my PC (behind hardware firewall). I noticed a lot of in-bound
| >traffic filtered by the firewall.
| >And so, I checked the firewall log file:
| >http://gfc.my.contact.bg/tests/2007-...all-log-01.txt
| >and noticed that a few hosts are trying to access some service - mostly
| >TCP:12824 that is filtered by the firewall. Being filtered means that
they
| >cannot determine if there is a host, unless they send a PING for it.
| >
| >My question is:
| >is the client software that stupid to repeat connection every quarter of
a
| >second?
| >or is that some attack against the previous owner of that IP?
| >or is that some Trojan client trying to access server on previous owner
of
| >that IP?
| >or why is that behaviour?
| >It makes no sense repeating the connection attempt that frequently,
unless
| >trying to flood the other side. Which also does not make sense because
this
| >IP is being assigned to clients of the ISP and not to a server, and flood
| >attacks are usually used to prevent access to a specific server.
| >
| >My action was to reset the DSL modem again and take a new "clean" IP for
the
| >DSL modem.
| >
| >I am also going to ask my ISP to configure the modem not to respond to
ICMP
| >packets.
| >
| >
| >
| >Thank you for any information and shared knowledge!
| >
| >George Valkov
| >
|
| George,
|
| Whenever I see an access attempted against a specific port, I look it up
in the
| ISC / SANS database.
| http://isc.sans.org/port.html?port=12824
|
| That shows 2 things:
| 1) There is an increasing amount of traffic against that port, being
reported.
| 2) Nobody knows what it is (If an attack port is known it will be
identified
| here, if anywhere).
|
| Bottom line is, you aren't alone. Watch the ISC page for updates.

Hello Chuck!
A few months ago, a link on you web site
http://nitecruzr.blogspot.com/
already led me to
http://isc.sans.org/
And there is also the Shields up at
https://www.grc.com/
These three are great places! :-) Thank you very much! :-)

George Valkov


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless network connection blocked by firewall Jill Wireless Networks 1 02-07-2008 01:41 AM
VPN Connection Blocked by firewall StegnerJ@gmail.com Windows Networking 2 04-04-2007 06:36 PM
MN-500 Blocking WAN Connection Attempts - How to stop? BN Broadband Hardware 4 03-02-2007 05:20 AM
Blocked Connection Attempts - Hacker attempts? =?Utf-8?B?Umlja0lzQnVnZ2Vk?= Broadband Hardware 2 05-05-2006 06:57 AM
VPN connection attempts in2minds Home Networking 0 10-29-2003 11:28 AM



1 2 3 4 5 6 7 8 9 10 11