![]() |
|
#1
|
||||
|
||||
|
@ Prevx
Hi, i know i've mentioned it before, but i've just caught WRSA trying to get out via UDP, why is this ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#2
|
||||
|
||||
|
DNS lookups, which the OS performs on behalf of applications automatically.
|
|
#3
|
||||
|
||||
|
Hi, Ok thanks for that
Strange why it should want to use UDP though, when ASFAIK it shouldn't do normally ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#4
|
|||
|
|||
|
Quote:
? DNS Lookups are normally done via UDP and have been for decades. RFC 1035 ( http://tools.ietf.org/html/rfc1035 ), circa 1987 Section 4.2.1 P3: "UDP is not acceptable for zone transfers, but is the recommended method for standard queries in the Internet." *Pulls out his Old Network Engineer cane, "You kids these days and yer newfangled AAAA records! Get off my lawn!"
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense My scans take 22 seconds. How long are yours?
|
|
#5
|
||||
|
||||
|
Quote:
Learn something new every day, Thanks It's curious that even though my FW blocks those UDP attempts, i don't have a problem surfing etc !
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#6
|
|||
|
|||
|
Quote:
UDP is the recommended manner per the RFC, but it can and will fall back to TCP if UDP doesn't work. The downside is the overhead in TCP in doing so. There's also a chance that your firewall is "inside" the system level of DNS, in which case it wouldn't see or block the normal system-level DNS lookups that can be tampered with by malware (and the hosts file). Or it could normally ignore the system-level DNS lookups.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense My scans take 22 seconds. How long are yours?
|
|
#7
|
||||
|
||||
|
@ Techfox1976
Thanks a LOT for the info How would i establish if "my firewall is "inside" the system level of DNS" ? I'm using ZA v.5.5.062.000 Don't laugh ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#8
|
|||
|
|||
|
Quote:
If the firewall can log "all" traffic, look for stuff from the System process (PID 0) to the DNS server set in your network config, port 53 UDP or TCP. Or any process other than WSA for that matter. Just loading a web page should initiate a request or seven for each page.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense My scans take 22 seconds. How long are yours?
|
|
#9
|
||||
|
||||
|
Quote:
__________________
Avira Free av|Comodo Firewall 5.12|MBAM Free.|Sandboxie.|Firefox Browser. For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world... |
|
#10
|
||||
|
||||
|
Quote:
Ya think @ Techfox1976 Sorry for the delay in replying ! Apart from WRSA which i allow, Zemana also tries out via that route, even though i have ALL the options set NOT to ? so i disallow it. Apart from those i always see this, when logging on, which i allow. Quote:
AFAIK that's normal.
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#11
|
|||
|
|||
|
Generic Host Process, which contains the DNS resolver. If that ever gets blocked, doooom shall be the result.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense My scans take 22 seconds. How long are yours?
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|