Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 12th, 2008, 12:22 AM
techcafe techcafe is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 13
Default firewall log - dns cache poisoning attack

i've noticed that my ESS firewall log shows an alarming number of Detected DNS cache poisoning attack and Incorrect IP packet checksum events. there was also a Detected Reverse TCP Desynchronization attack event.

the DNS cache poisoning events made reference to the IP address of my ISP's DNS servers (i verified the IPs) as the Source; and the Reverse Desync attack made reference to a source IP address belonging to a friend whom i was having a skype conversation with at the time.

anyone else notice stuff like this in their firewall log?


i should probably mention, i've enabled the Troubleshooting Log options at the bottom of the IDS and advanced options panel (under the Personal firewall tree), so perhaps i'm seeing stuff that isn't normally logged, since those two logging options are disabled by default.
  #2  
Old February 12th, 2008, 08:39 AM
wrathchild wrathchild is offline
Regular Poster
 
Join Date: Feb 2008
Location: Neoplantesis
Posts: 170
Default Re: firewall log - dns cache poisoning attack

Probably false...but maybe not...who knows?! Bad thing is that you'll receive answers from members and not from ESET people.

I wish to see the rules which block this type of attacks, not only checkboxes...only then we will know how ESS block this attacks!

ESS had a lot of problems with firewall from early beta to final (not resolved yet)...and I simply don't trust in their firewall. I hope that in next version this segment will be much better.
  #3  
Old February 12th, 2008, 09:18 AM
JasSolo's Avatar
JasSolo JasSolo is offline
Frequent Poster
 
Join Date: May 2007
Location: Denmark
Posts: 414
Default Re: firewall log - dns cache poisoning attack

I have the same attacks....tons of them. In fact every 4th minute or so.


Cheers
  #4  
Old February 13th, 2008, 04:31 AM
Jenee Jenee is offline
Regular Poster
 
Join Date: Dec 2007
Posts: 185
Default Re: firewall log - dns cache poisoning attack

I have the two log options you mentioned turned on and none of my PCs have those log entries that you mention except I have seen a couple of the reverse TCP Desynchronization.
It may be that something is trying to get into your PC via the ports that are open legitimately.
  #5  
Old February 13th, 2008, 08:15 AM
nickster_uk nickster_uk is offline
Regular Poster
 
Join Date: Feb 2006
Posts: 183
Default Re: firewall log - dns cache poisoning attack

I contacted ESET about this a while ago and they told me it was a bug in the firewall. While some may be genuine threats, it's unlikely all are especially if you see them getting logged every few seconds.

They told me it would be addressed in future builds..but since then, a couple of new builds have been released but the problem persists.

In the meantime, if it bothers you too much, you could always disable the 'DNS poisoning attack detection' option in the firewall options.

Coincidently, I also use a couple of POP mail gadgets in my sidebar and whenever the 'DNS poisoning attack detection' option is enabled, I frequently get DNS errors and connection timeout errors in the gadgets, but as soon as it's disabled, everything works without a problem.

Hope ESET sort this as it's a bit of a concern...although, aside from that, I think it's a great firewall/AV package.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:24 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums