Comp01
September 28th, 2003, 10:49 PM
Another weird connection request 9I blocked it, but saved the request details to a text file)
Here are the details (From Sygate):
Connection origin :
File Version :******4.10.2222
File Description :***Windows 32-bit VxD Message Server
File Path :******C:\WINDOWS\SYSTEM\MSGSRV32.EXE
Process ID :******FFFF314F (Heximal) 4294914383 (Decimal)
***local initiated
Protocol :******ICMP
Local Address : ******.***.**.**
ICMP Type :******10 (Router Solicitation)
ICMP Code : ******0
Remote Name :*********
Remote Address :***224.0.0.2
Ethernet packet details:
Ethernet II (Packet Length: 44)
***Destination: ***01-00-5e-00-00-02
***Source: ***00-00-f8-77-39-d7
Type: IP (0x0800)
Internet Protocol
***Version: 4
***Header Length: 20 bytes
***Flags:
******.0.. = Don't fragment: Not set
******..0. = More fragments: Not set
***Fragment offset:0
***Time to live: 128
***Protocol: 0x1 (ICMP - Internet Control Message Protocol)
***Header checksum: 0xc66 (Correct)
***Source: 209.165.23.45
***Destination: 224.0.0.2
Internet Control Message Protocol
***Type: 10 (Router Solicitation)
***Code: 0
***Data (4 bytes)
Binary dump of the packet:
0000: 01 00 5E 00 00 02 00 00 : F8 77 39 D7 08 00 45 00 | ..^......w9...E.
0010: 00 1C 0C 00 00 00 80 01 : 66 0C D1 A5 17 2D E0 00 | ........f....-..
0020: 00 02 0A 00 F5 FF 00 00 : 00 00 42 00 | ..........B.
Edit: removed Comp01's IP address
Here are the details (From Sygate):
Connection origin :
File Version :******4.10.2222
File Description :***Windows 32-bit VxD Message Server
File Path :******C:\WINDOWS\SYSTEM\MSGSRV32.EXE
Process ID :******FFFF314F (Heximal) 4294914383 (Decimal)
***local initiated
Protocol :******ICMP
Local Address : ******.***.**.**
ICMP Type :******10 (Router Solicitation)
ICMP Code : ******0
Remote Name :*********
Remote Address :***224.0.0.2
Ethernet packet details:
Ethernet II (Packet Length: 44)
***Destination: ***01-00-5e-00-00-02
***Source: ***00-00-f8-77-39-d7
Type: IP (0x0800)
Internet Protocol
***Version: 4
***Header Length: 20 bytes
***Flags:
******.0.. = Don't fragment: Not set
******..0. = More fragments: Not set
***Fragment offset:0
***Time to live: 128
***Protocol: 0x1 (ICMP - Internet Control Message Protocol)
***Header checksum: 0xc66 (Correct)
***Source: 209.165.23.45
***Destination: 224.0.0.2
Internet Control Message Protocol
***Type: 10 (Router Solicitation)
***Code: 0
***Data (4 bytes)
Binary dump of the packet:
0000: 01 00 5E 00 00 02 00 00 : F8 77 39 D7 08 00 45 00 | ..^......w9...E.
0010: 00 1C 0C 00 00 00 80 01 : 66 0C D1 A5 17 2D E0 00 | ........f....-..
0020: 00 02 0A 00 F5 FF 00 00 : 00 00 42 00 | ..........B.
Edit: removed Comp01's IP address