Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 24th, 2013, 11:55 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,860
Question UDP ?

@ Prevx

Hi, i know i've mentioned it before, but i've just caught WRSA trying to get out via UDP, why is this ?

Click image for larger version

Name:	wrsa.png
Views:	2
Size:	4.7 KB
ID:	236994
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #2  
Old February 25th, 2013, 01:35 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: UDP ?

DNS lookups, which the OS performs on behalf of applications automatically.
  #3  
Old February 26th, 2013, 12:12 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,860
Thumbs up Re: UDP ?

Hi, Ok thanks for that

Strange why it should want to use UDP though, when ASFAIK it shouldn't do normally ?
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #4  
Old February 26th, 2013, 08:31 AM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 582
Default Re: UDP ?

Quote:
Originally Posted by CloneRanger
Hi, Ok thanks for that

Strange why it should want to use UDP though, when ASFAIK it shouldn't do normally ?

?
DNS Lookups are normally done via UDP and have been for decades.

RFC 1035 ( http://tools.ietf.org/html/rfc1035 ), circa 1987
Section 4.2.1 P3:
"UDP is not acceptable for zone transfers, but is the recommended method
for standard queries in the Internet."

*Pulls out his Old Network Engineer cane, "You kids these days and yer newfangled AAAA records! Get off my lawn!"
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
  #5  
Old February 26th, 2013, 10:28 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,860
Default Re: UDP ?

Quote:
Originally Posted by Techfox1976

DNS Lookups are normally done via UDP and have been for decades

Learn something new every day, Thanks

It's curious that even though my FW blocks those UDP attempts, i don't have a problem surfing etc !
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #6  
Old February 27th, 2013, 08:45 PM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 582
Default Re: UDP ?

Quote:
Originally Posted by CloneRanger
Learn something new every day, Thanks

It's curious that even though my FW blocks those UDP attempts, i don't have a problem surfing etc !

UDP is the recommended manner per the RFC, but it can and will fall back to TCP if UDP doesn't work. The downside is the overhead in TCP in doing so.

There's also a chance that your firewall is "inside" the system level of DNS, in which case it wouldn't see or block the normal system-level DNS lookups that can be tampered with by malware (and the hosts file). Or it could normally ignore the system-level DNS lookups.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
  #7  
Old February 28th, 2013, 06:42 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,860
Default Re: UDP ?

@ Techfox1976

Thanks a LOT for the info

How would i establish if "my firewall is "inside" the system level of DNS" ? I'm using ZA v.5.5.062.000 Don't laugh
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #8  
Old March 1st, 2013, 07:09 PM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 582
Default Re: UDP ?

Quote:
Originally Posted by CloneRanger
@ Techfox1976

Thanks a LOT for the info

How would i establish if "my firewall is "inside" the system level of DNS" ? I'm using ZA v.5.5.062.000 Don't laugh

If the firewall can log "all" traffic, look for stuff from the System process (PID 0) to the DNS server set in your network config, port 53 UDP or TCP. Or any process other than WSA for that matter. Just loading a web page should initiate a request or seven for each page.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
  #9  
Old March 1st, 2013, 07:20 PM
AMIGA500's Avatar
AMIGA500 AMIGA500 is online now
Very Frequent Poster
 
Join Date: May 2012
Location: United Kingdom.
Posts: 2,678
Default Re: UDP ?

Quote:
Originally Posted by CloneRanger
@ Techfox1976

Thanks a LOT for the info

How would i establish if "my firewall is "inside" the system level of DNS" ? I'm using ZA v.5.5.062.000 Don't laugh
Your ZA is due a major update lol.
__________________
Avira Free av|Comodo Firewall 5.12|MBAM Free.|Sandboxie.|Firefox Browser.

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
  #10  
Old March 5th, 2013, 10:39 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,860
Default Re: UDP ?

Quote:
Originally Posted by Beethoven1770

Your ZA is due a major update lol.

Ya think

@ Techfox1976

Sorry for the delay in replying ! Apart from WRSA which i allow, Zemana also tries out via that route, even though i have ALL the options set NOT to ? so i disallow it. Apart from those i always see this, when logging on, which i allow.

Quote:
Description Generic Host Process for Win32 Services requested permission to access the internet.
Rating High
Date / Time 2013/03/05 05:41:20-5:00 GMT
Type Repeat Program
Program C:\WINDOWS2\System32\svchost.exe
Source IP
Destination IP 0.0.0.0:53
Direction Outgoing (connect)
Action Taken Allowed (once)/Manual
Count 1
Source DNS
Destination DNS


AFAIK that's normal.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #11  
Old March 5th, 2013, 10:11 PM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 582
Default Re: UDP ?

Generic Host Process, which contains the DNS resolver. If that ever gets blocked, doooom shall be the result.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:36 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums