<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Can someone please shed some light on this Alert? in Security</title>
<link>http://www.dslreports.com/forum/r12856235</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 00:47:13 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 00:47:13 EDT</lastBuildDate>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12876129</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : <div class="bquote"><SMALL>said by  richtig <A HREF="/useremail/u/773102"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Hi, Allan<br><br>If you *join*, your anonymity (other than what you choose to reveal :D) is guaranteed here, and there are possibilities for private messages on this server. As it is, your posts are revealing ip addresses and domains...<br> </DIV>My apologies. I did not mean to say that ip addresses are being revealed:huh:. Not on these posts. Of course your ip address is in every packet ;).<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12876129</guid>
<pubDate>Thu, 10 Mar 2005 06:55:03 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please shed some light on this Alert?</title>
<link>http://www.dslreports.com/forum/remark,12868924</link>
<description><![CDATA[<A HREF="/useremail/u/805291"><b>dandelion</b></A> : I spoke too soon-just got the message again right before I signed on to my computer after signing on, no more messages (firewall is supposed to prevent any communication when in screensaver mode):<br>Rule "Block Window File Sharing" blocked communication local address (my router) process name is "system", the popup said it was blocked on 0.0.0.0. but I don't see that on the log.(do you get this message right before signon?)<br><SMALL>--<br><A HREF="http://www.bbrteamhelix.net/">want to know what I'm doing? </A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12868924</guid>
<pubDate>Wed, 09 Mar 2005 13:43:22 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12866856</link>
<description><![CDATA[<A HREF="/useremail/u/653770"><b>TheWiseGuy</b></A> : <div class="bquote"><SMALL>said by temp-name:</SMALL><br><br>Hi,<br><br>Yes, I have WEP enabled. Although I have come across numerous WEP cracking tools while looking around...not sure of their success however.<br> </DIV>Yes WEP can be cracked, and I guess if it has been on your network, someone could be using DHCP to obtain an IP and use your network. The packet in that alert would not be a hack attack on your computer. I think it would be interesting to see the rule details as  jvmorris <A HREF="/useremail/u/360338"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> has stated.<br><SMALL>--<br>Dog and Butterfly</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12866856</guid>
<pubDate>Wed, 09 Mar 2005 09:13:02 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please shed some light on this Alert?</title>
<link>http://www.dslreports.com/forum/remark,12865838</link>
<description><![CDATA[<A HREF="/useremail/u/805291"><b>dandelion</b></A> : I'm not very proficient in security, nor wireless and am still learning, but I have NIS 2005, and a D-link wireless 624 with wpa security on the router (these nice folks in this forum helped me change from wep to wpa &raquo;<A HREF="/forum/dlink">D-Link</A> )<br>NIS was also warning of an "attack" on my computer from the same address. At the time I had window's setting up my wireless, switched to my Atheros Client Utility and allowed access for that program in NIS and no more warnings. I'm just assuming I had something set up wrong in my firewall:).<br><SMALL>--<br><A HREF="http://www.bbrteamhelix.net/">want to know what I'm doing? </A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12865838</guid>
<pubDate>Wed, 09 Mar 2005 03:36:04 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12865508</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Hi, Allan<br><br>If you *join*, your anonymity (other than what you choose to reveal :D) is guaranteed here, and there are possibilities for private messages on this server. As it is, your posts are revealing ip addresses and domains...<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12865508</guid>
<pubDate>Wed, 09 Mar 2005 01:49:30 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12861620</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Okay, just item 4) for me . . .<br><br><div class="bquote"><SMALL>said by temp-name:</SMALL><br><br>. . . .<br>4) Hi jvmorris - how would I get the details you mention i.e. "Could we have some details on the specifics of the rule and what it was intended to accomplish". That's a little above my head. I know that Norton IS is essentially configured as it would be out of the box. I think the only thing changes was that I bumped the security level up to the maximum (from memory, I set it to Supervisor...or similar). . . .<br> </DIV>Well, the <I>first</I> thing you need to do is find the rule in question, the one labeled simply "Firewall Rule".  I was rather hoping you yourself might know how to do this, since the version of NIS I'm currently running is NIS 2002 and Symantec has changed the User Interface since then.  In the olden days, you'd open up the NIS console from the System Tray, select "Personal Firewall" and then click on "internet access control" (but I don't think it works this way anymore).  I'm fairly certain that the rule in question is in what is now referred to as the "General Rules" (used to be System-Wide Rules) category.  If nothing else, it's obviously not application-specific and the Rule Action appears to be set to IGNORE, rather than BLOCK or PERMIT.  <br><br>If you can't find the rule on your own, we're going to have to wait until one of the NIS 2004/2005 users shows up and tells you how to find it.<br><br>Once you <I>find</I> the rule, you need to examine the rule details.  To do that, you select the rule labeled "Firewall Rule" and then click on the command button that's labeled "Modify" (or somesuch).  No, you're not going to modify the rule, this is simply the only way you're going to get to the details of the rule.  So when you're finished recording the following information, just cancel out of the resulting window.<br><br>At any rate, at this point, you'll get a new window (probably labeled "Modify Rule" with six tabs.  Unfortunately, you're going to have to step through each of these tabs and write down the user-modifiable inputs manually in order to post them here.<br><br>I think the first tab will be labeled Action and you'll find the "Monitor Internet Access" option selected.  The next tab will probably be labeled Connections and you will probably find one of two options selected here: either "Connections from other computers" or "Connections to and from other computers".  The third tab is most likely labeled Computers.  There are any number of options that might be specified here, but I suspect it's most likely "Any Computer".  The next tab is most likely labeled Communications and I'm not going to tell you what I expect to find here, but I think you're likely to find multiple options (at least two) (one for protocol and at least one for ports).  Need to know the <B>specific</B> details in both fields.  Next tab is labeled  Tracking.  What's selected there?  The final tab is labeled Description and that's where you're going to find the label of "Firewall Rule".<br><br>Write all this down (very carefully) and post it back here.    There are (thankfully rare) occasions in which a rule can get corrupted and that's why it's so important to be very precise about what you find in these fields.<br><br>In the good ole days, it was quite simple to use a third-party utility to do this.  For example, here's what I would find in NIS 2002: <br><div class="code"><PRE><span class="codetext">  <br>Rule 1          Monitor Ports<br>Category:       NIS System Keeping<br>Rule in use:    YES<br>Logging:        NO<br>Protocol:       TCP or UDP<br>Action:         Ignore <br>Direction:      Either  <br>Application:    Any Application<br>Local  service: Any Service<br>Local  Address: Any Address<br>Remote Service:  <br>..........Port: 110<br>Remote Address: Any Address<br> </SPAN></PRE></DIV><br>But that's all gone now and you have to do it the hard way. :(<br><br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12861620</guid>
<pubDate>Tue, 08 Mar 2005 18:39:53 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12861194</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi,<br><br>Yes, I have WEP enabled. Although I have come across numerous WEP cracking tools while looking around...not sure of their success however.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12861194</guid>
<pubDate>Tue, 08 Mar 2005 17:56:24 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12861039</link>
<description><![CDATA[<A HREF="/useremail/u/653770"><b>TheWiseGuy</b></A> : Do you have the wireless router/modem secured with encryption?<br><SMALL>--<br>Dog and Butterfly</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12861039</guid>
<pubDate>Tue, 08 Mar 2005 17:39:11 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please explain this Alert</title>
<link>http://www.dslreports.com/forum/remark,12860864</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi everyone<br><br>Firstly, thank you all for your responses.<br><br>I'll just try and answer your questions as best I can:<br><br>1) These alerts can happen anytime i.e. last night while I was simply doing some work from home at about 9.41pm two alerts appeared (one of which is the IS log I posted)<br><br>2) My laptop uses DHCP. My partner occassionaly uses here work laptop on the network (they're the only two computers we have) but the alerts appeared when she wasn't on.<br><br>3) I am vigilant when it comes to Norton IS (version 2005) updates and windows updates. I'm running XP SP2 all fully updated.<br><br>4) Hi jvmorris - how would I get the details you mention i.e. "Could we have some details on the specifics of the rule and what it was intended to accomplish". That's a little above my head. I know that Norton IS is essentially configured as it would be out of the box. I think the only thing changes was that I bumped the security level up to the maximum (from memory, I set it to Supervisor...or similar)<br><br>5) My Router is a DLink ADSL Wireless Router Modem 54mbps + 4port 10/100 (Model 604t)<br><br>Ummm..I think that's it. Thanks again guys<br><br>Allan]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12860864</guid>
<pubDate>Tue, 08 Mar 2005 17:21:43 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please shed some light on this Ale</title>
<link>http://www.dslreports.com/forum/remark,12858744</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Yeah, that's the way I read the log event he posted.<br><br>But, let's back up a bit for a moment on that rule itself.  If that's the <I>only</I> event he's got at the time the Alert popped up, something needs a bit of tuning here regarding the rule itself.<br><br>First, it looks like a rule in what I believe is now called the General Rules section of NIS rules (used to be called system-wide rules).  Furthermore, it looks like a user-customized rule in which both logging and alerting have been invoked.  Not knowing exactly what the rule itself states, I would certainly advise turning off the alerting.<br><br>Well, hold on a sec. . . . Maybe something else is wrong with the way the rule is configured.  Could we have some details on the specifics of the rule and what it was intended to accomplish?  (I don't think it's one of the default rules, if only due to the label on the rule.)<br><br><B>Addendum:</B>  I also think it must be a custom rule because the action indicated is IGNORE; I don't believe that there are any default rules in NIS with an action of IGNORE (i.e., Monitor, Log Only).<br><SMALL>--<br>Regards,<br>    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12858744</guid>
<pubDate>Tue, 08 Mar 2005 13:19:02 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please shed some light on this Ale</title>
<link>http://www.dslreports.com/forum/remark,12857685</link>
<description><![CDATA[<A HREF="/useremail/u/653770"><b>TheWiseGuy</b></A> : Are there other computers on the network. Do they use DHCP to obtain an IP from the router? The packet above is a broadcast and is a DHCP discovery packet which is a normal part of the process of a computer obtaining an IP, on boot, if it is using DHCP.<br><br>For more info on how DHCP works a good link is<br>&raquo;<A HREF="http://support.microsoft.com/?kbid=169289" >support.microsoft.com/?kbid=169289</A><br><SMALL>--<br>Dog and Butterfly</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12857685</guid>
<pubDate>Tue, 08 Mar 2005 11:13:09 EDT</pubDate>
</item>

<item>
<title>Re: Can someone please shed some light on this Ale</title>
<link>http://www.dslreports.com/forum/remark,12857226</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Does this happen when you deliberately re-boot either the router the laptop? If so, it is probably only a small configuration problem.<br><br>You should have a thorough read of<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8698">How do I secure a wireless network (wireless router)?</A><br>or<br>&raquo;<A HREF="http://www2.dslreports.com/faq/8698" >www2.dslreports.com/faq/8698</A><br>(there may be issues with one or other of these links for some people)<br><br>While you are doing all of that :uhh:, let's hope that you can get someone who knows both the router config options and NIS.<br><br>Questions you will need to answer<br><br>* versions of NIS and any updates done<br>* exact model of router, firmware version, etc.<br><br>And while I am at it, what is the update status of Windows XP? I can not emphasize enough that it ought to be fully updated, unless there are any <I>known</I> incompatibilities with the Vaio. Do you have a firewall elsewhere? Is the Windows Security Center turned on? Is the Internet Connection Firewall On or Off? What is the update status of the anti-viral component of NIS? What is running on the Vaio when this happens?<br><br>You may need to be patient. If in doubt, please wait for an expert answer. Meanwhile you should plan to be back here as much as possible, so please register so that we can get to know you!<br><br>Hmmm.. the header wants someone to shed light on an Ale. :D<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12857226</guid>
<pubDate>Tue, 08 Mar 2005 10:10:32 EDT</pubDate>
</item>

<item>
<title>Can someone please shed some light on this Alert?</title>
<link>http://www.dslreports.com/forum/remark,12856235</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi<br><br>I'm running a wireless ADSL network at home with my Vaio Laptop to a DLINK Wirless ADSL Modem Router. It's a new laptop, running XP Pro and has Norton Internet Security 2005 installed.<br><br>Occasionally of late I keep getting these Norton alerts popping up that say "A recent attempt to attack your computer...etc etc". Something about an inbound UDP connection. Does anyone know what this means? I checked through the security logs and found these lines were recorded at the same time the alert appeared:<br><br>Details: Rule "Firewall Rule" ignored (0.0.0.0,bootps(67)).<br>Inbound UDP packet.<br>Local address,service is (255.255.255.255,bootps(67)).<br>Remote address,service is (0.0.0.0,bootpc(68)).<br>Process name is "N/A".<br> <br>Maybe I'm just being paranoid, but I've noticed lately that another wireless network has been appearing in range of my network at home. A friend pointed me towards an app called NetStumber which when run, lists any wireless networks in range. My initial panic therefore was that the person running this nearby network also knows that I exist and is somehow attempting to access my computer.<br><br>Could the two be related? Can someone please translate what the Norton IS log is actually reporting?<br><br>Many, many thanks<br>Al]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12856235</guid>
<pubDate>Tue, 08 Mar 2005 06:03:47 EDT</pubDate>
</item>

</channel>
</rss>
