CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Firewall itself keeps connecting?

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
markwolk

Lieutenant
Lieutenant
Premium Member

Joined: Sep 06, 2004
Posts: 151
Location: New Zealand
Premium

PostPosted: Thu Aug 17, 2006 2:16 am    Post subject: Firewall itself keeps connecting?
Reply with quote

I have Filseclab firewall, which I find very simple to use, yet highly customisable. Recently I looked up its "Monitor" showing all the traffic in real time, and I was surprised to see that, seemingly, the firewall itself constantly attempts some connection which may look as follows:

Code:
Digital Signature: Signed by Filseclab
Description: Filseclab Personal Firewall
Product Name: Filseclab Personal Firewall
Company Name: Filseclab
File Version: 3.0
Description: Filseclab Personal Firewall Professional Edition
Rules: 27
Action: Pass
Application: xfilter
Protocol/Direction: UDP/Out
Local IP/Port: 192.168.1.255/137
Remote IP/Port: 192.168.1.9/137
Sent/Recv: 0/92
Time: 14:02:23
Description: RECV|RT:10|No.27 Application Rules
Rules description: Grants to get remote host name


This is happening as I do not use the PC for anything at all. Should I worry?


_________________
www.travel-university.org
Back to top
View users profile Send private message Visit posters website
CdMaN83

MIRT Hunter


Joined: Jul 27, 2006
Posts: 19
Location: Romania

PostPosted: Thu Aug 17, 2006 4:34 am    Post subject:
Reply with quote

Not really because all the connections are local to the network (the 192.168 range is a private ip range), possibly even local to your machine (do a ipconfig to find out if your machine has the ip of 192.168.1.9). It is possible that the firewall uses the IP protocol to communicate between its components.

Back to top
View users profile Send private message Visit posters website Yahoo Messenger
markwolk

Lieutenant
Lieutenant
Premium Member

Joined: Sep 06, 2004
Posts: 151
Location: New Zealand
Premium

PostPosted: Thu Aug 17, 2006 5:06 am    Post subject:
Reply with quote

Yes; you are right: this is my machine's IP. Still, I don't think it was happening before Confused


_________________
www.travel-university.org
Back to top
View users profile Send private message Visit posters website
Paranoid2000

Lieutenant
Lieutenant


Joined: Jun 16, 2005
Posts: 285
Location: North West, United Kingdom

PostPosted: Sat Aug 19, 2006 6:05 pm    Post subject:
Reply with quote

That report doesn't look right - it reports the "Local Address" (which should be your PC) as 192.168.1.255 which is not a valid computer address, it is reserved for broadcast use (i.e. sending a message to every computer on the 192.168.1.x network). I'd suggest you query this with Filseclab since it seems to be a bug.

Port 137 is part of the NetBIOS protocol, used for Windows file and printer sharing - so Windows itself is sending out such packets, rather than the firewall. If you do not share files or printers on your network, you can disable NetBIOS which should prevent these reports in future - GKWeb's WWDC being one easy way of doing this.

Back to top
View users profile Send private message
markwolk

Lieutenant
Lieutenant
Premium Member

Joined: Sep 06, 2004
Posts: 151
Location: New Zealand
Premium

PostPosted: Sat Aug 19, 2006 9:45 pm    Post subject:
Reply with quote

Thanks for the contribution. This WWDC looked like an interesting software, so I downloaded it. I do not share files or printers on my network, so I disabled NetBIOS as you suggest (+ I also disabled everything else as suggested in the interface). I have restarted my laptop twice; however the interface still shows "NetBIOS will be DISABLED after the next REBOOT". And the same traffic still occurs. Any ideas on what I should do next?


_________________
www.travel-university.org
Back to top
View users profile Send private message Visit posters website
Paranoid2000

Lieutenant
Lieutenant


Joined: Jun 16, 2005
Posts: 285
Location: North West, United Kingdom

PostPosted: Sun Aug 20, 2006 2:37 pm    Post subject:
Reply with quote

Check that you have disabled NetBIOS over TCP/IP as detailed here.

Back to top
View users profile Send private message
markwolk

Lieutenant
Lieutenant
Premium Member

Joined: Sep 06, 2004
Posts: 151
Location: New Zealand
Premium

PostPosted: Sun Aug 20, 2006 7:27 pm    Post subject:
Reply with quote

Great reference advice; thanks! That did the trick.


_________________
www.travel-university.org
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer