CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

DNS problem in the latest version?

 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Tull

Guest
IP: 87.16.*.*






PostPosted: Tue May 30, 2006 8:16 am    Post subject: DNS problem in the latest version?
Reply with quote

I don't use predefined rules. I created this rule in advanced packet filter rules:

OUTGOING direction
LOCAL PORTS: 1024-4999
REMOTE PORT: 53
PROTOCOL: UDP
IP: my ISP domain name servers DNS

With this new KPF version sometimes Internet Explorer wants to use local port greater than 4999 and remote port 53 to my ISP domain name server why? Is it a bug of this new version?

Back to top
Tull

Guest
IP: 87.16.*.*






PostPosted: Tue May 30, 2006 8:18 am    Post subject: Re: DNS problem in the latest version?
Reply with quote

APPLICATION: svchost.exe

Back to top
IP: 194.146.*.*

Guest






PostPosted: Tue May 30, 2006 2:40 pm    Post subject:
Reply with quote

So, is it IE or svchost?

Well, svchost has the right to use anything between 1025 and 65535. You've created a wrong rule.

X.

Back to top
steveUK

Guest
IP: 84.68.*.*






PostPosted: Tue May 30, 2006 4:49 pm    Post subject:
Reply with quote

I use the DNS rules from the well known and tested BZ rules for KPF 2.x, which are 1024-5000, UDP 53, my ISP, "both" ways. Still works fine here, but could depend on your setup/ISP.

Back to top
Tull

Guest
IP: 82.52.*.*






PostPosted: Tue May 30, 2006 5:43 pm    Post subject:
Reply with quote

KPF prompted me for an outgoing connection with local port 1124, but my rules have been configured for 1024-4999. IE and all others windows applications resolve the DNS using svchost but with the lastest KPF build sometimes the DSN rules seem not working. I'm pretty sure.

Back to top
Tull

Guest
IP: 82.52.*.*






PostPosted: Tue May 30, 2006 5:50 pm    Post subject:
Reply with quote

I think that the bug is due IE predefined rule created by the latest KPF build, I can't remove that rule! But I set that IE rule as ASK, because I configured IE using advanced packet filter rule. May be advanced packet filter rule is in conflit with IE predefined rule and or svchost? I think this is a bug.

Back to top
steveUK

Guest
IP: 84.66.*.*






PostPosted: Wed May 31, 2006 5:04 pm    Post subject:
Reply with quote

My packet rules for DNS are for "any application". On mine, svchost.exe is only used for windows updates. All other applications request there own DNS access including IE. I have DNS client off (caching) for my Hosts file to work, this is probably why.

"KPF prompted me for an outgoing connection with local port 1124"

- What application is actually asking for this access? If its Internet Explorer, then add that to your rule or change to "any application" like me.

Back to top
Tull

Guest
IP: 82.61.*.*






PostPosted: Thu Jun 01, 2006 6:57 am    Post subject:
Reply with quote

steveUK wrote:

- What application is actually asking for this access? If its Internet Explorer, then add that to your rule or change to "any application" like me.



All Windows XP applications use svchost.exe to resolve IP addresses using my ISP domanin name servers, in fact it's since many years I use KPF4 and I have create a rule for svchost and every applications resolve own address using that rule without problems. But only with this latest KPF build sometimes, maybe for a bug, I see that IE doesn't use svchost (this happens only 1 time and not every day, but this happens!) and so KPF prompt me.

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer