- Posts: 5
- Thank you received: 0
DNS problem
19 years 8 months ago #7686
by moustik
DNS problem was created by moustik
Hello,
I receive more packet for my computer (my firewall has a bad configuration) but the packets was ignored.
but a mechanism running (perhaps a malware) and when i receive a packet : my computer contact the server DNS and resolve name of the computer and a final packet of the computer send to me.
I have constated that's reccurent web site who contact me but he have a many web site. (one site all five second)
And when i launch my connexion, no web site is contacted.
an idea ?
I receive more packet for my computer (my firewall has a bad configuration) but the packets was ignored.
but a mechanism running (perhaps a malware) and when i receive a packet : my computer contact the server DNS and resolve name of the computer and a final packet of the computer send to me.
I have constated that's reccurent web site who contact me but he have a many web site. (one site all five second)
And when i launch my connexion, no web site is contacted.
an idea ?
- FallenZer0
- Offline
- Premium Member
Less
More
- Posts: 259
- Thank you received: 0
19 years 8 months ago #7691
by FallenZer0
-There Is A Foolish Corner In The Brain Of The Wisest Man- Aristotle
Replied by FallenZer0 on topic Re: DNS problem
Only if I could have understood your problem.
-There Is A Foolish Corner In The Brain Of The Wisest Man- Aristotle
19 years 8 months ago #7695
by sahirh
Sahir Hidayatullah.
Firewall.cx Staff - Associate Editor & Security Advisor
tftfotw.blogspot.com
Replied by sahirh on topic Re: DNS problem
Can you try and make that a bit clearer...?
It sounds like you've got some malware installed.. perhaps Ad-aware or a virus scan is what you need.
Cheers,
It sounds like you've got some malware installed.. perhaps Ad-aware or a virus scan is what you need.
Cheers,
Sahir Hidayatullah.
Firewall.cx Staff - Associate Editor & Security Advisor
tftfotw.blogspot.com
19 years 8 months ago #7701
by moustik
Replied by moustik on topic Re: DNS problem
No virus, no malware found.
In normal state, i receive an packet by an another computer, this packet is ignored.
In ambigous state, i receive a packet, it's not ignored because server dns is contacted to resolve the IP. And after, i receive a final packet who is ignored.
Normal state : blabla.com:5430 ----> Mycomputer:4445 it'terminated
Ambigous mode : blalbla.com:54300
> Mycomputer:2115
Mycomputer:dns ----> ServerDNS:dns query for bla...
ServerDNS:dns ----> MyComputer:dns resp IP to bla.
And it resolve name of all packet that i receive
In normal state, i receive an packet by an another computer, this packet is ignored.
In ambigous state, i receive a packet, it's not ignored because server dns is contacted to resolve the IP. And after, i receive a final packet who is ignored.
Normal state : blabla.com:5430 ----> Mycomputer:4445 it'terminated
Ambigous mode : blalbla.com:54300
> Mycomputer:2115
Mycomputer:dns ----> ServerDNS:dns query for bla...
ServerDNS:dns ----> MyComputer:dns resp IP to bla.
And it resolve name of all packet that i receive
19 years 8 months ago #7703
by cyberoidx
Surya Sharma
www.Technodrome.info
AR3 Y0U T3CH ENOUGH FOR IT?
Replied by cyberoidx on topic Re: DNS problem
:shock: Is that clear? :shock:
Got any original error messages/screenshots?
Got any original error messages/screenshots?
Surya Sharma
www.Technodrome.info
AR3 Y0U T3CH ENOUGH FOR IT?
19 years 8 months ago #7727
by moustik
Replied by moustik on topic Re: DNS problem
If you know ethereal that's clear !
I have change my firewall Norton antivirus for outpost.
I have block this external traffic
But i have a task system in my computer who make that.
I have a process system and a traffic netbios blocked in local by outpost.
Computer try to scan other computer.
If my IP is 83.155.170.81 computer who an IP in 83.155.*.* are scanned (port 3191, 4528, 3764....)
I suppose that a bot server is contacted and send more results.
Best attack or best scan ?!?!?
No virus found with Norton, No-adware found with spybot and Ad-aware
I have change my firewall Norton antivirus for outpost.
I have block this external traffic
But i have a task system in my computer who make that.
I have a process system and a traffic netbios blocked in local by outpost.
Computer try to scan other computer.
If my IP is 83.155.170.81 computer who an IP in 83.155.*.* are scanned (port 3191, 4528, 3764....)
I suppose that a bot server is contacted and send more results.
Best attack or best scan ?!?!?
No virus found with Norton, No-adware found with spybot and Ad-aware
Time to create page: 0.130 seconds