techcafe
February 12th, 2008, 12:22 AM
i've noticed that my ESS firewall log shows an alarming number of Detected DNS cache poisoning attack and Incorrect IP packet checksum events. there was also a Detected Reverse TCP Desynchronization attack event.
the DNS cache poisoning events made reference to the IP address of my ISP's DNS servers (i verified the IPs) as the Source; and the Reverse Desync attack made reference to a source IP address belonging to a friend whom i was having a skype conversation with at the time.
anyone else notice stuff like this in their firewall log?
i should probably mention, i've enabled the Troubleshooting Log options at the bottom of the IDS and advanced options panel (under the Personal firewall tree), so perhaps i'm seeing stuff that isn't normally logged, since those two logging options are disabled by default.
the DNS cache poisoning events made reference to the IP address of my ISP's DNS servers (i verified the IPs) as the Source; and the Reverse Desync attack made reference to a source IP address belonging to a friend whom i was having a skype conversation with at the time.
anyone else notice stuff like this in their firewall log?
i should probably mention, i've enabled the Troubleshooting Log options at the bottom of the IDS and advanced options panel (under the Personal firewall tree), so perhaps i'm seeing stuff that isn't normally logged, since those two logging options are disabled by default.