<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Norton Internet Security Problem! in Security</title>
<link>http://www.dslreports.com/forum/r14810645</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 10:42:06 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 10:42:06 EDT</lastBuildDate>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14826128</link>
<description><![CDATA[<A HREF="/useremail/u/1196782"><b>Red Dragon</b></A> : I also just remembered something about NIS. This should not be occurring every minute or so. Under default setting NIS will auto block IPs that make an intrusion attempt. Unless auto block is disabled or set to a bizarre low ban time then this should not be occurring. Also 255.255.255 and IPs like then remind me of subnet masks. kind of makes sense since it is pointing back to your own computer as the attacker. You could also try windows repair function for you net connection to see if that helps.<br><SMALL>--<br>That light that you see at the end of the tunnel. You know that reealy bright one; well its not salvation. Its the 6 o'clock freight train</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14826128</guid>
<pubDate>Thu, 17 Nov 2005 13:04:57 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14825183</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>I'm afraid you're going to have to either hire someone or find a friendly neighborhood geek to help you.  It's just about impossible to properly train you quickly via a web forum.  It's really up to you to read and research (and experiment!) until you understand.<br><br>But really, I'm not sure you have a problem worth putting all that time into.<br><br>What I mean is, a strange packet every minute is not a big deal; again I suggest you get a router.  My suspicion is simply that your firewall is screwy; you could uninstall / reinstall NIS and/or try a different firewall product.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14825183</guid>
<pubDate>Thu, 17 Nov 2005 11:00:29 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14825163</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : I can't understand the help section of ethereal, I don't know how to use it can someone help me please? Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14825163</guid>
<pubDate>Thu, 17 Nov 2005 10:57:24 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14824966</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : For more than you could want to know, check the Router section of the FAQ at &raquo;<A HREF="/faq/security/3.%20NAT%20Routers">Security</A><br><br>In brief, the original poster appears to have a public IP address.  A layer of NAT routing between him or her and the Internet is a valuable (and one might argue essential) safety measure.  (With a private IP address, unsolicited inbound packets get no further than your router.)<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14824966</guid>
<pubDate>Thu, 17 Nov 2005 10:24:22 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14824197</link>
<description><![CDATA[<A HREF="/useremail/u/1196782"><b>Red Dragon</b></A> : <div class="bquote"><SMALL>said by SamN :</SMALL><br><br>what will buying a router do?<br> </DIV>? It would stop that mess from appearing on his computer. The packets would be blocked at the router. Ever hear of NAT?<br><SMALL>--<br>That light that you see at the end of the tunnel. You know that reealy bright one; well its not salvation. Its the 6 o'clock freight train</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14824197</guid>
<pubDate>Thu, 17 Nov 2005 07:39:58 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14824075</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : what will buying a router do?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14824075</guid>
<pubDate>Thu, 17 Nov 2005 06:49:26 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14820745</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : All ethereal is going to do is give you a <I>capability</I> to capture the packets; you still have to enable it and I believe what that involves is described (in excuciating detail) in the accompanying documentation.<br><br>Mind, I've never done this myself, so yes I'm talking off the top of me head. :)<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14820745</guid>
<pubDate>Wed, 16 Nov 2005 18:18:02 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14820617</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : Thank you. I have downloaded 'ethereal' and i have installed it.....what do i do now to 'track' the packet(s)? Thanks so much for help]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14820617</guid>
<pubDate>Wed, 16 Nov 2005 18:03:06 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14819184</link>
<description><![CDATA[<A HREF="/useremail/u/1014996"><b>ranschultz</b></A> : <A HREF="http://www.ethereal.com">Ethereal</A> is a popular open source packet sniffer for Windows. The ethernet address (aka MAC or NIC address) will appear in every packet that it tracks. A user's guide is available to give you guidance on using it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14819184</guid>
<pubDate>Wed, 16 Nov 2005 14:54:10 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14817981</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : Also, how do I use a packet sniffer? How do I get the 'ethernet address'?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14817981</guid>
<pubDate>Wed, 16 Nov 2005 12:18:00 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14816138</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : Which 'packet sniffer' do you recommend?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14816138</guid>
<pubDate>Wed, 16 Nov 2005 06:36:55 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14813629</link>
<description><![CDATA[<A HREF="/useremail/u/1014996"><b>ranschultz</b></A> : This appears to be a smurf type of attack. Somebody on your local segment is sending this packet with the intent of using your machine to amplify the attack and cause a denial of service to your segment or some machine on your segment.<br><br>To figure out who it is you'd have to use a packet sniffer to get the ethernet address associated with the offending packet and associate that with an Internet address. Reporting the ethernet address alone to your ISP should be sufficient to track this person down.<br><br>Edit: fixed a bone-headed wording mistake.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14813629</guid>
<pubDate>Tue, 15 Nov 2005 20:34:47 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14811932</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Looks like it's coming from NIS' IDS subsystem, rather than the firewall.  Pity it doesn't give more details about the ICMP message involved.<br><br>Maybe Reese can shed some light on this.<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14811932</guid>
<pubDate>Tue, 15 Nov 2005 16:54:34 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14811891</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : Here's an example from my activity log:<br><br>Details: Intrusion: Invalid Source IP Address.<br>Intruder: 255.255.255.255.<br>Risk Level: Medium.<br>Source IP address: 255.255.255.255.This IP address is invalid.<br>Destination IP address: YOUR-JSAHFDNCU3(84.13.89.247).<br>Protocol: ICMP.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14811891</guid>
<pubDate>Tue, 15 Nov 2005 16:50:00 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14811024</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Okay,  found the earlier thread.  It's at &raquo;<A HREF="/forum/remark,14790612">NIS2006</A> .<br><br>Did it look like this?  (Probably not, I see that's an outbound attempt and it sounds like you're talking a inbound attempt.)<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14811024</guid>
<pubDate>Tue, 15 Nov 2005 14:51:52 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14810732</link>
<description><![CDATA[<A HREF="/useremail/u/1014996"><b>ranschultz</b></A> : As Mr. Morris suggests, a detailed log entry would be appreciated. Short of, or, in addition to that, can you provide the full text of the show details? It would be helpful to know what kind of intrusion is being attempted.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14810732</guid>
<pubDate>Tue, 15 Nov 2005 14:12:38 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14810689</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>Reboot.<br><br>And get I suggest you get a router.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14810689</guid>
<pubDate>Tue, 15 Nov 2005 14:06:02 EDT</pubDate>
</item>

<item>
<title>Re: Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14810658</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Can you copy and paste the whole message from the NIS firewall event log?<br><br>It sort of sounds like something that someone else saw a few days back.<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14810658</guid>
<pubDate>Tue, 15 Nov 2005 14:02:38 EDT</pubDate>
</item>

<item>
<title>Norton Internet Security Problem!</title>
<link>http://www.dslreports.com/forum/remark,14810645</link>
<description><![CDATA[<A HREF="/useremail/u/1282543"><b>jellybeans27</b></A> : my problem is that literally every minute i get a pop-up in the bottom right hand corner of my screen saying 'an intrusion attempt has been blocked.' So i click it to find out more and i click 'show details' and it says the intruder is 255.255.255.255 and under source IP address it says '255.255.255.255.This IP address is invalid.' It also says that the destination IP address is 'YOUR-JSAHFDNCU3(84.13.89.247).' Which is me (my computer name and IP address at that time). What is causing this to happen EVERY SINGLE MINUTE? Please help, Thank you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14810645</guid>
<pubDate>Tue, 15 Nov 2005 14:00:46 EDT</pubDate>
</item>

</channel>
</rss>
