M
MEB
PCR and Gram Pappy [among others] have been discussing firewall settings and
what they can or should be used for.
In the spirit of those discussions, I thought I would post some blocked
activity from a SINGLE session/contact through my ISP and ONLY to this news
server and my email accounts [via OE6]. This is from the firewall log
[several of my normal settings/restrictions were specifically reset for this
presentation].
No other Internet activity occurred [e.g., no external IE or browser usage
or other activity]. All *allowed activity* has been removed, so that the
addresses and activities blocked might be addressed for perhaps a greater
understanding of the function of firewalls, what they can and are used for,
and other aspects related thereto.
For those who do not understand firewalls, these activities would or may
have been allowed as they followed either programs IN USE [allowed
activity], or through addressing [broadcast or otherwise] had a firewall not
been used.
NOTE: this is contact through a dial-up connection[phone]/ISP [which is
indicated via some of these addresses], ALWAYS ON connections are even more
of a security risk.
Hopefully, this discussion will be useful to those interested and provide
theory and answers to various issues.
Rule sets or other settings for various firewalls would naturally be of
interest.
1,[28/Jul/2007 01:33:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 67.170.2.174:43511->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:00] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.112.1.7:8806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 218.10.137.139:55190->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 218.10.137.139:55190->localhost:1027, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.46.171.127:41806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:10] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.46.171.127:41806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:35:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 189.153.168.143:32737->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:35:46] Rule 'Packet to unopened port received': Blocked:
In UDP, 58.49.103.227:1107->localhost:1434, Owner: no owner
1,[28/Jul/2007 01:36:04] Rule 'Packet to unopened port received': Blocked:
In TCP, 219.148.119.6:12200->localhost:7212, Owner: no owner
1,[28/Jul/2007 01:36:08] Rule 'Packet to unopened port received': Blocked:
In TCP, 219.148.119.6:12200->localhost:8000, Owner: no owner
1,[28/Jul/2007 01:36:08] Rule 'TCP ack packet attack': Blocked: In TCP,
msnews.microsoft.com [207.46.248.16:119]->localhost:1186, Owner: no owner
1,[28/Jul/2007 01:36:12] Rule 'Packet to unopened port received': Blocked:
In UDP, 90.20.19.204:46983->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:36:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 87.235.125.80:8052->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:36:50] Rule 'Packet to unopened port received': Blocked:
In UDP, 69.126.6.107:32338->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:37:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 189.128.113.251:16491->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:37:38] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.209.110.13:49282->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:37:38] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.209.110.13:49282->localhost:1027, Owner: no owner
1,[28/Jul/2007 01:38:02] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.117.180.230:22925->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:10] Rule 'Packet to unopened port received': Blocked:
In UDP, 74.120.200.92:45097->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:16] Rule 'Packet to unopened port received': Blocked:
In UDP, host230.200-117-180.telecom.net.ar
[200.117.180.230:22925]->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 88.22.213.173:19033->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:56] Rule 'Packet to unopened port received': Blocked:
In UDP, 74.107.240.241:48641->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:39:22] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.208.208.95:53699->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:39:54] Rule 'Packet to unopened port received': Blocked:
In UDP, 67.81.156.51:20406->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:40:46] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.89.49.207:23085->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:40:58] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.208.208.90:33490->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:42:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 142.161.209.54:15611->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:42:52] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.60.89.179:47922->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:43:20] Rule 'TCP ack packet attack': Blocked: In TCP,
msnews.microsoft.com [207.46.248.16:119]->localhost:1185, Owner: no owner
1,[28/Jul/2007 01:43:40] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.31.24.235:50988->localhost:29081, Owner: no owner
--
MEB
http://peoplescounsel.orgfree.com
________
what they can or should be used for.
In the spirit of those discussions, I thought I would post some blocked
activity from a SINGLE session/contact through my ISP and ONLY to this news
server and my email accounts [via OE6]. This is from the firewall log
[several of my normal settings/restrictions were specifically reset for this
presentation].
No other Internet activity occurred [e.g., no external IE or browser usage
or other activity]. All *allowed activity* has been removed, so that the
addresses and activities blocked might be addressed for perhaps a greater
understanding of the function of firewalls, what they can and are used for,
and other aspects related thereto.
For those who do not understand firewalls, these activities would or may
have been allowed as they followed either programs IN USE [allowed
activity], or through addressing [broadcast or otherwise] had a firewall not
been used.
NOTE: this is contact through a dial-up connection[phone]/ISP [which is
indicated via some of these addresses], ALWAYS ON connections are even more
of a security risk.
Hopefully, this discussion will be useful to those interested and provide
theory and answers to various issues.
Rule sets or other settings for various firewalls would naturally be of
interest.
1,[28/Jul/2007 01:33:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 67.170.2.174:43511->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:00] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.112.1.7:8806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 218.10.137.139:55190->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 218.10.137.139:55190->localhost:1027, Owner: no owner
1,[28/Jul/2007 01:34:06] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.46.171.127:41806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:34:10] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.46.171.127:41806->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:35:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 189.153.168.143:32737->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:35:46] Rule 'Packet to unopened port received': Blocked:
In UDP, 58.49.103.227:1107->localhost:1434, Owner: no owner
1,[28/Jul/2007 01:36:04] Rule 'Packet to unopened port received': Blocked:
In TCP, 219.148.119.6:12200->localhost:7212, Owner: no owner
1,[28/Jul/2007 01:36:08] Rule 'Packet to unopened port received': Blocked:
In TCP, 219.148.119.6:12200->localhost:8000, Owner: no owner
1,[28/Jul/2007 01:36:08] Rule 'TCP ack packet attack': Blocked: In TCP,
msnews.microsoft.com [207.46.248.16:119]->localhost:1186, Owner: no owner
1,[28/Jul/2007 01:36:12] Rule 'Packet to unopened port received': Blocked:
In UDP, 90.20.19.204:46983->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:36:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 87.235.125.80:8052->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:36:50] Rule 'Packet to unopened port received': Blocked:
In UDP, 69.126.6.107:32338->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:37:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 189.128.113.251:16491->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:37:38] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.209.110.13:49282->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:37:38] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.209.110.13:49282->localhost:1027, Owner: no owner
1,[28/Jul/2007 01:38:02] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.117.180.230:22925->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:10] Rule 'Packet to unopened port received': Blocked:
In UDP, 74.120.200.92:45097->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:16] Rule 'Packet to unopened port received': Blocked:
In UDP, host230.200-117-180.telecom.net.ar
[200.117.180.230:22925]->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:30] Rule 'Packet to unopened port received': Blocked:
In UDP, 88.22.213.173:19033->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:38:56] Rule 'Packet to unopened port received': Blocked:
In UDP, 74.107.240.241:48641->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:39:22] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.208.208.95:53699->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:39:54] Rule 'Packet to unopened port received': Blocked:
In UDP, 67.81.156.51:20406->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:40:46] Rule 'Packet to unopened port received': Blocked:
In UDP, 200.89.49.207:23085->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:40:58] Rule 'Packet to unopened port received': Blocked:
In UDP, 221.208.208.90:33490->localhost:1026, Owner: no owner
1,[28/Jul/2007 01:42:36] Rule 'Packet to unopened port received': Blocked:
In UDP, 142.161.209.54:15611->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:42:52] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.60.89.179:47922->localhost:29081, Owner: no owner
1,[28/Jul/2007 01:43:20] Rule 'TCP ack packet attack': Blocked: In TCP,
msnews.microsoft.com [207.46.248.16:119]->localhost:1185, Owner: no owner
1,[28/Jul/2007 01:43:40] Rule 'Packet to unopened port received': Blocked:
In UDP, 190.31.24.235:50988->localhost:29081, Owner: no owner
--
MEB
http://peoplescounsel.orgfree.com
________