ceejay13
May 1st, 2004, 01:35 PM
Apologies if this in in the wrong part of the forum.
Just installed Look'n'Stop firewall, trying to get my head around things and looking at the logs, came across an entry that showed my PC was trying to contact this IP address which came up with like this on a Whois was done:
05/01/04 18:13:40 IP block 239.255.255.250
Trying 239.255.255.250 at ARIN
Trying 239.255.255 at ARIN
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 224.0.0.0 - 239.255.255.255
CIDR: 224.0.0.0/4
NetName: MCAST-NET
NetHandle: NET-224-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: FLAG.EP.NET
NameServer: STRUL.STUPI.SE
NameServer: NS.ISI.EDU
NameServer: NIC.NEAR.NET
Comment: This block is reserved for special purposes.
Comment: Please see RFC 3171 for additional information.
Comment:
RegDate: 1991-05-22
Updated: 2002-09-16
OrgAbuseHandle: IANA-IP-ARIN
OrgTechHandle: IANA-IP-ARIN
There is no Reverse DNS when a lookup was done.
Now, my question is, What is the 'special purposes' mentioned above, who is running the IP address and should I allow this to happen??
It was a UDP protocol from my port 3755 to their 1900 and the packet contained this:
0000:4D 2D 53 45 41 52 43 48 M-SEARCH
0008:20 2A 20 48 54 54 50 2F * HTTP/
0010:31 2E 31 0D 0A 48 6F 73 1.1..Hos
0018:74 3A 32 33 39 2E 32 35 t:239.25
0020:35 2E 32 35 35 2E 32 35 5.255.25
0028:30 3A 31 39 30 30 0D 0A 0:1900..
0030:53 54 3A 75 70 6E 70 3A ST:upnp:
0038:72 6F 6F 74 64 65 76 69 rootdevi
0040:63 65 0D 0A 4D 61 6E 3A ce..Man:
0048:22 73 73 64 70 3A 64 69 "ssdp:di
0050:73 63 6F 76 65 72 22 0D scover".
0058:00 00 00 00 00 00 00 00 ........
0060:00 .
Now it may be innocent, but I don't like the words "ssdp:discover"
Anyone know what this is about?
BTW, like this forum, it appears to be objective and more to the point, relatively up to date.
Just installed Look'n'Stop firewall, trying to get my head around things and looking at the logs, came across an entry that showed my PC was trying to contact this IP address which came up with like this on a Whois was done:
05/01/04 18:13:40 IP block 239.255.255.250
Trying 239.255.255.250 at ARIN
Trying 239.255.255 at ARIN
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 224.0.0.0 - 239.255.255.255
CIDR: 224.0.0.0/4
NetName: MCAST-NET
NetHandle: NET-224-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: FLAG.EP.NET
NameServer: STRUL.STUPI.SE
NameServer: NS.ISI.EDU
NameServer: NIC.NEAR.NET
Comment: This block is reserved for special purposes.
Comment: Please see RFC 3171 for additional information.
Comment:
RegDate: 1991-05-22
Updated: 2002-09-16
OrgAbuseHandle: IANA-IP-ARIN
OrgTechHandle: IANA-IP-ARIN
There is no Reverse DNS when a lookup was done.
Now, my question is, What is the 'special purposes' mentioned above, who is running the IP address and should I allow this to happen??
It was a UDP protocol from my port 3755 to their 1900 and the packet contained this:
0000:4D 2D 53 45 41 52 43 48 M-SEARCH
0008:20 2A 20 48 54 54 50 2F * HTTP/
0010:31 2E 31 0D 0A 48 6F 73 1.1..Hos
0018:74 3A 32 33 39 2E 32 35 t:239.25
0020:35 2E 32 35 35 2E 32 35 5.255.25
0028:30 3A 31 39 30 30 0D 0A 0:1900..
0030:53 54 3A 75 70 6E 70 3A ST:upnp:
0038:72 6F 6F 74 64 65 76 69 rootdevi
0040:63 65 0D 0A 4D 61 6E 3A ce..Man:
0048:22 73 73 64 70 3A 64 69 "ssdp:di
0050:73 63 6F 76 65 72 22 0D scover".
0058:00 00 00 00 00 00 00 00 ........
0060:00 .
Now it may be innocent, but I don't like the words "ssdp:discover"
Anyone know what this is about?
BTW, like this forum, it appears to be objective and more to the point, relatively up to date.