Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 29th, 2007, 07:02 AM
Ciaba Ciaba is offline
Infrequent Poster
 
Join Date: May 2006
Posts: 22
Default Jetico 1.x UDP inbound on port 0(zero)

...hi all, any know what kind of event is this?

http://img257.imageshack.us/img257/9...0bisxd8.th.jpg
  #2  
Old May 29th, 2007, 07:23 AM
hiro hiro is offline
Banned
 
Join Date: Jul 2005
Posts: 77
Default Re: Jetico 1.x UDP inbound on port 0(zero)

Hi, Ciaba

- is receive datagram on port 0, you can block this port.
- (perché non fai domande al tuo forum materno)
  #3  
Old May 29th, 2007, 01:16 PM
Ciaba Ciaba is offline
Infrequent Poster
 
Join Date: May 2006
Posts: 22
Default Re: Jetico 1.x UDP inbound on port 0(zero)

...perchè non ti fai i caz.i tuoi e mi lasci vivere in pace?
  #4  
Old May 29th, 2007, 01:59 PM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,555
Default Re: Jetico 1.x UDP inbound on port 0(zero)

Quote:
Originally Posted by Ciaba
...perchè non ti fai i caz.i tuoi e mi lasci vivere in pace?

LOL... a real gentleman

Fax
  #5  
Old May 29th, 2007, 02:51 PM
Climenole's Avatar
Climenole Climenole is offline
Look 'n' Stop Expert
 
Join Date: Jun 2005
Posts: 1,640
Smile Re: Jetico 1.x UDP inbound on port 0(zero)

Hi Ciaba

Quote:
Originally Posted by Ciaba
...hi all, any know what kind of event is this?

May be an other MS Net Send Messenger spam...

Most of the time they are sent on UDP ports 1026, 1027 and 1028 from any remote port including the port 0 ...

The included data looks like this :

« ALERT...

SYSTEM ERROR !..
System Error detected
in C:\WINDOWS\system32
Windows suggests visiting www.BLAH BLAH BLAH cleanthispc.com
to download free repair tool

ALERT...

Windows has encounted an Internal Error.
Your registry is corrupted..
.http:// BLAH BLAH BLAH msreg.com..To repair your system
ASAP!!.

ALERT...

STOP
WINDOWS REQUIRES IMMEDIATE ATTENTION...
Windows has found CRITICAL SYSTEM ERRORS...
To fix the errors please do the following:
1. Download Registry Repair from: http:// www.BLAH BLAH BLAH winregfix32.com.
2. Install Registry Repair.
3. Run Registry Repair.
4. Reboot your computer.
FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION!..
»

and other stOOpids messages...

They comes mostly from zombie PCs in the Pacific ring (check the IP addresses range..)

[220.*.*.*] , [222.*.*.*], etc.

Ref.: http://www.microsoft.com/windowsxp/u.../stopspam.mspx

If Windows is up-to-date this service is disabled.
And your FW block this: that's okay.

By the way: all packets from or to the port 0 must be blocked...


__________________
Claude LaFrenière
  #6  
Old May 29th, 2007, 07:36 PM
Ciaba Ciaba is offline
Infrequent Poster
 
Join Date: May 2006
Posts: 22
Default Re: Jetico 1.x UDP inbound on port 0(zero)

...hey Climenole, tnx for explanations, my system is up to date and no errors event, I've yet bloked that port but why from eMule? I've looking for IP and are from many different phone companyes...so not blacklisted IP range or similar. Is possible a DoS acrivity?

Last edited by Ciaba : May 30th, 2007 at 01:20 AM.
  #7  
Old May 29th, 2007, 07:57 PM
Ciaba Ciaba is offline
Infrequent Poster
 
Join Date: May 2006
Posts: 22
Default Re: Jetico 1.x UDP inbound on port 0(zero)

Quote:
Originally Posted by fax
LOL... a real gentleman

Fax

...The class is not whater.
  #8  
Old May 29th, 2007, 08:11 PM
Climenole's Avatar
Climenole Climenole is offline
Look 'n' Stop Expert
 
Join Date: Jun 2005
Posts: 1,640
Smile Re: Jetico 1.x UDP inbound on port 0(zero)

Hi Ciaba

Quote:
Originally Posted by Ciaba
...hey Cimenole, tnx for explanations, my system is up to date and no errors event, I've yet bloked that port but why from eMule? I've looking for IP and are from many different phone companyes...so not blacklisted IP range or similar. Is possible a DoS acrivity?

eMule ? Check yout rule set!
NetSendMessenger spam packets can't be interfere with UDP packets to eMule...

eMule reject these packets since they don't have the data and format required to be relayed in this p2p network...

Don't waste your time to check from where these NSM spam come from...
It comes from Zombies PC. They are remotly controlled by spammers and they used them for relaying the spam. (In pacific ring, est europa and so on...)

No Denial of Service with this.
With Windows up-to-date and theese packets blocked by the firewall nothings can happen...

__________________
Claude LaFrenière
  #9  
Old May 30th, 2007, 01:22 AM
Ciaba Ciaba is offline
Infrequent Poster
 
Join Date: May 2006
Posts: 22
Default Re: Jetico 1.x UDP inbound on port 0(zero)

...oki man, tx for so...
  #10  
Old May 30th, 2007, 05:47 AM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,555
Default Re: Jetico 1.x UDP inbound on port 0(zero)

Quote:
Originally Posted by Ciaba
...The class is not whater.

LOL

Fax
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:30 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums