Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 17th, 2012, 08:57 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question I have a problem

Hi

Last week I have installed ESS V.5. latest version and I have been seeing the "Detected DNS cache poisoning attack on average about 50-100 times a day so far

I read @ ESET Knowledgebase
http://kb.eset.com/esetkb/index?page...nt&id=SOLN2933


I understand it is an ESS issue, Why bother to fix it by following the instructions?

I decided to downgrade to ESS V.4.X (latest version) and a friend of mine use my computer meanwhile I was out of the town.

Just out of curiosity, How do I know how many Detected DNS cache poisoning attack messages my friend received in ESS V.4.X GUI OR log file?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #2  
Old October 17th, 2012, 09:56 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: I have a problem

V5 detects the same attacks as v4 except that it notifies the user when an attack is detected instead of just logging it in the firewall log. Attack notifications can be disabled in v5 and newer.
What are the source IP addresses of these DNS cache poisoning attacks?
  #3  
Old October 18th, 2012, 03:37 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by Marcos
V5 detects the same attacks as v4 except that it notifies the user when an attack is detected instead of just logging it in the firewall log. Attack notifications can be disabled in v5 and newer.
What are the source IP addresses of these DNS cache poisoning attacks?

V5: Most of them are: Source 10.3.77.26:53 Target 197.168.0.122:1040

Then if V5 notifies the user when an attack is detected, and v4 does not...

V4: I do not know How many Detected DNS cache poisoning attack messages I have meanwhile my friend was using my compute, How can I found out?

Thank you
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered

Last edited by rebelscum0000 : October 18th, 2012 at 08:48 AM.
  #4  
Old October 19th, 2012, 08:26 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by Marcos
V5 detects the same attacks as v4 except that it notifies the user when an attack is detected instead of just logging it in the firewall log. Attack notifications can be disabled in v5 and newer.
What are the source IP addresses of these DNS cache poisoning attacks?

Hello?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #5  
Old October 22nd, 2012, 04:01 PM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Angry Re: I have a problem

Quote:
Originally Posted by Marcos
V5 detects the same attacks as v4 except that it notifies the user when an attack is detected instead of just logging it in the firewall log. Attack notifications can be disabled in v5 and newer.
What are the source IP addresses of these DNS cache poisoning attacks?

Where is the official Eset support forum? Could you be son kind to provide me the link?

TIA
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #6  
Old October 22nd, 2012, 04:19 PM
SweX SweX is online now
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,652
Default Re: I have a problem

Quote:
Originally Posted by rebelscum0000
Where is the official Eset support forum?
You are writing in it right now

I guess that you are waiting for an reply from Marcos/or other ESET Mod?
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #7  
Old October 22nd, 2012, 04:23 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: I have a problem

Does the IP address 10.3.77.26 belong to your Internet provider's DNS server?
  #8  
Old October 23rd, 2012, 03:44 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Default Re: I have a problem

Quote:
Originally Posted by Marcos
Does the IP address 10.3.77.26 belong to your Internet provider's DNS server?

Yes, Confirmed with my ISP and ipconfig /all

And once again my main question

I downgrade to V.4
How do I know How many DNS cache poisoning attacks I have meanwhile my friend was using my computer and I was out of the town?

V.4 GUI Or Log File?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered

Last edited by rebelscum0000 : October 23rd, 2012 at 03:52 AM.
  #9  
Old October 23rd, 2012, 08:25 AM
encus encus is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 531
Default Re: I have a problem

Quote:
Originally Posted by rebelscum0000
Yes, Confirmed with my ISP and ipconfig /all

And once again my main question

I downgrade to V.4
How do I know How many DNS cache poisoning attacks I have meanwhile my friend was using my computer and I was out of the town?

V.4 GUI Or Log File?
For ESS v4, you can view all the attacks in the firewall log.

Good luck!
  #10  
Old October 23rd, 2012, 10:50 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by encus
For ESS v4, you can view all the attacks in the firewall log.

Good luck!

Thank sir, But I can not find the firewall logs

Where are they located?

Windows XP Pro SP3

TIA
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #11  
Old October 25th, 2012, 10:43 AM
encus encus is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 531
Default Re: I have a problem

Quote:
Originally Posted by rebelscum0000
Thank sir, But I can not find the firewall logs

Where are they located?

Windows XP Pro SP3

TIA
1. Open ESS main menu
2. Click Tools -> Log
3. From drop down menu, select Personal Firewall Log

HTH.
  #12  
Old October 25th, 2012, 06:44 PM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by encus
1. Open ESS main menu
2. Click Tools -> Log
3. From drop down menu, select Personal Firewall Log

HTH.

Thank you but Using the V.4 GUI and following your intructions The Eset Personal firewall log is empty, I do not understand why i can not view all the attacks in the firewall log.

Or If I need to post my firewall Log, here @ this forum, where is located the log file?

Windows XP SP3

Thanks in advance for any help you can provide me
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #13  
Old October 30th, 2012, 03:32 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
I Say! Re: I have a problem

Hello?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #14  
Old October 30th, 2012, 04:34 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: I have a problem

There are no differences in DNS cache poisoning detection between v4 and v5 as both utilize the same firewall module which includes the functionality for attack detetections. If the attack is not detected any more with v4, it shouldn't be detected after installing v5 either.
  #15  
Old October 31st, 2012, 12:13 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by Marcos
Does the IP address 10.3.77.26 belong to your Internet provider's DNS server?

i confirmed the IP address 10.3.77.26 belong to my Internet provider's DNS server then is a real attack?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #16  
Old November 5th, 2012, 09:03 AM
SweX SweX is online now
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,652
Default Re: I have a problem

Quote:
Originally Posted by rebelscum0000
Thank you but Using the V.4 GUI and following your intructions The Eset Personal firewall log is empty, I do not understand why i can not view all the attacks in the firewall log.

Or If I need to post my firewall Log, here @ this forum, where is located the log file?

Windows XP SP3

Thanks in advance for any help you can provide me
You need to enable logging of the firewall so the firewall log will be filled with information.
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #17  
Old November 6th, 2012, 11:14 AM
BellaBoo's Avatar
BellaBoo BellaBoo is offline
Regular Poster
 
Join Date: May 2009
Location: SydYork, US of Oz
Posts: 114
Default Re: I have a problem

how to upload a pic ... this poster needs a visual!

Click image for larger version

Name:	Someone elses intrusion scap.JPG
Views:	3
Size:	81.2 KB
ID:	235366

did that work!??!

HA thar it beeee!

OP, tick the yellow highlighted box then click OK. after a short while, your log will reveal the relevant activity.

fyi, google the offending ip addy/s to identify them.

i had a couple intruders (from china and germany) but it turned out they were just *looking* [common, recurring attempts] so i ran checks on my computer using ShieldsUp! via grc.com and i was satisfied with the results: my computer provided zero access.

so i unchecked the box 'Display notification afer attack detection' box [see above pic under intrusion detection]

HTH

good luck, btw!

edited to add necessay clarification
__________________

Roxy
'techno was made for people who can't dance' ~ Rt, twitter, 16 May 2009

Win7 Pro x64, v.6.1.7601, SP1
AMD Phenom(tm) II X6 1055T Processor (2800 MHz), 12288 MB RAM, AMD Radeon 6800 Series
OS: Office 2010 ProPlus

Last edited by BellaBoo : November 6th, 2012 at 12:51 PM.
  #18  
Old November 12th, 2012, 01:33 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by BellaBoo
how to upload a pic ... this poster needs a visual!

Attachment 235366

did that work!??!

HA thar it beeee!

OP, tick the yellow highlighted box then click OK. after a short while, your log will reveal the relevant activity.

fyi, google the offending ip addy/s to identify them.

i had a couple intruders (from china and germany) but it turned out they were just *looking* [common, recurring attempts] so i ran checks on my computer using ShieldsUp! via grc.com and i was satisfied with the results: my computer provided zero access.

so i unchecked the box 'Display notification afer attack detection' box [see above pic under intrusion detection]

HTH

good luck, btw!

edited to add necessay clarification

Thank you very much and sorry for the delay, using ShieldsUp my IP is dynamic I will never pass the test, so I can not run checks in my computer any other suggestion?
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #19  
Old November 20th, 2012, 09:45 AM
BellaBoo's Avatar
BellaBoo BellaBoo is offline
Regular Poster
 
Join Date: May 2009
Location: SydYork, US of Oz
Posts: 114
Default Re: I have a problem

hey rebel sorry, i missed your post...

even tho your IP is dynamic [about which i know nothing], did you at least try ShieldsUp!?

i have no other suggestions for you, but perhaps with the passage of time, you've been able to work out something.

if not, good luck in your endeavours
__________________

Roxy
'techno was made for people who can't dance' ~ Rt, twitter, 16 May 2009

Win7 Pro x64, v.6.1.7601, SP1
AMD Phenom(tm) II X6 1055T Processor (2800 MHz), 12288 MB RAM, AMD Radeon 6800 Series
OS: Office 2010 ProPlus
  #20  
Old November 20th, 2012, 09:55 AM
BellaBoo's Avatar
BellaBoo BellaBoo is offline
Regular Poster
 
Join Date: May 2009
Location: SydYork, US of Oz
Posts: 114
Default Re: I have a problem

so, i researched dynamic IP and i came up with this: http://whatismyipaddress.com/dynamic-static

it says tho that and i quote: ... Dynamic IP addressing assigns a different IP address each time the ISP customer logs on to their computer, ...! so, if that were the case, ShieldsUp! will scan your computer during your current computer session and if there are any hiccups, they'll be revealed. so, it doesn't matter the ip addy, it matters that your computer is silent to the outside world.

unless however: If you have Dynamic IP Addressing through your Website Host it means that you are sharing an IP Address with several other customers. in which case, ShieldsUp! would be pointless.
__________________

Roxy
'techno was made for people who can't dance' ~ Rt, twitter, 16 May 2009

Win7 Pro x64, v.6.1.7601, SP1
AMD Phenom(tm) II X6 1055T Processor (2800 MHz), 12288 MB RAM, AMD Radeon 6800 Series
OS: Office 2010 ProPlus
  #21  
Old November 28th, 2012, 04:08 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by BellaBoo
hey rebel sorry, i missed your post...

even tho your IP is dynamic [about which i know nothing], did you at least try ShieldsUp!?

i have no other suggestions for you, but perhaps with the passage of time, you've been able to work out something.

if not, good luck in your endeavours

Thank you BellaBoo, yup I tried ShieldsUp! but I was not sure
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #22  
Old November 28th, 2012, 04:10 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Quote:
Originally Posted by BellaBoo
so, i researched dynamic IP and i came up with this: http://whatismyipaddress.com/dynamic-static

it says tho that and i quote: ... Dynamic IP addressing assigns a different IP address each time the ISP customer logs on to their computer, ...! so, if that were the case, ShieldsUp! will scan your computer during your current computer session and if there are any hiccups, they'll be revealed. so, it doesn't matter the ip addy, it matters that your computer is silent to the outside world.

unless however: If you have Dynamic IP Addressing through your Website Host it means that you are sharing an IP Address with several other customers. in which case, ShieldsUp! would be pointless.

OK I will try again, Thank you very much
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #23  
Old November 28th, 2012, 04:16 AM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Question Re: I have a problem

Hi,

Could be a possibility that I am receiving DNS cache poisoning detection since I am sending from my Mac massive emails to my Outlook Express?

Thanks in advance for any help you can provide me

Win XP SP3
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
  #24  
Old November 28th, 2012, 11:41 AM
dwomack's Avatar
dwomack dwomack is offline
Eset Moderator
 
Join Date: Mar 2011
Posts: 585
Default Re: I have a problem

This could be a possibility. What the KB article does not state is the various reasons that your IP address could be triggering the DNS Cache Poisoning Attack Detections. This is because there are simply too many reasons to reasonably list and we don't want to speculate on causes without complete information.

I've seen this happen with non-standard data traffic or when the router pings your network to verify it's still connected. There are many other reasons for the detection to be triggered. The IP addresses you provided for the Source (ISP) and Target (you) are within the safe range so it's very likely one of these reasons (including the one you gave) could be the reason you have seen these notifications. Again, without complete information, it's hard to speculate. It might be worth placing a call or submitting a support ticket with your local ESET distributor for more efficient support: http://www.eset-la.com/soporte/contacto
__________________
Resources: KnowledgebaseFacebook (US) • @ESET@ESETNASupportNewsBlog • YouTube: ESETKnowledgebase and esetusa
  #25  
Old November 28th, 2012, 02:33 PM
rebelscum0000's Avatar
rebelscum0000 rebelscum0000 is offline
Regular Poster
 
Join Date: Oct 2006
Location: Mexico City
Posts: 67
Thumbs up Re: I have a problem

Quote:
Originally Posted by dwomack
This could be a possibility. What the KB article does not state is the various reasons that your IP address could be triggering the DNS Cache Poisoning Attack Detections. This is because there are simply too many reasons to reasonably list and we don't want to speculate on causes without complete information.

I've seen this happen with non-standard data traffic or when the router pings your network to verify it's still connected. There are many other reasons for the detection to be triggered. The IP addresses you provided for the Source (ISP) and Target (you) are within the safe range so it's very likely one of these reasons (including the one you gave) could be the reason you have seen these notifications. Again, without complete information, it's hard to speculate. It might be worth placing a call or submitting a support ticket with your local ESET distributor for more efficient support: http://www.eset-la.com/soporte/contacto

Thank you sir
__________________
Regards


REAL-TIME : Outpost Firewall Pro LIFETIME LICENSE, NOD 32, Shadow Defender, Sandboxie Paid , Prevx 3.0, Hitman Pro, SpywareBlaster
ON-DEMAND: MBAM Pro, SAS Pro Real Time Protection,
BACKUP : Acronis True Image 2011 Registered
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:57 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums