PDA

View Full Version : Firewall Question


Mithrilhall
07-31-04, 06:45 PM
Does anyone here use Sygate's Firewall? Does anyone have a clue what these are?

This is the second time I have received these messages in the log viewer:

Active Response Disengaged
Active Response
Intrusion Detection System


A Whois on the IP address returned this:

% This is the RIPE Whois server.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/ripencc/pub-services/db/copyright.html

i netnum: 195.137.31.0 - 195.137.31.255
netname: FREEDOM2SURF
descr: Freedom To Surf plc
country: GB
admin-c: DT8-RIPE
tech-c: CP17-RIPE
tech-c: NP31-RIPE
rev-srv: server0004.freedom2surf.net
rev-srv: server0001.freedom2surf.net
status: ASSIGNED PA
mnt-by: F2S-NOC
changed: nick@freedom2surf.net 20040413
remarks: INFRA-AW
source: RIPE


This is the description of the Intrusion Detection:

E20059 BACKDOOR NetMetro File List

InvisiBill
08-02-04, 07:04 AM
Get a real firewall that just shows the local program/port and the remote IP/port it's connecting to?

An Intrusion Detection System is designed to detect attacks. However, many of the personal ones are known for not working well. Some will detect any ping as being some sort of attempted attack.

http://www.pestpatrol.com/pestinfo/n/netmetro.asp is info on NetMetro. The IDS reports it as "NetMetro File List", so they're probably just scanning your PC to see if it's infected with NetMetro. Or it's a valid request that the IDS is mistakenly reporting as NetMetro.

Chromite
08-02-04, 05:10 PM
Sygate does show that. He just didn't post that info.

Mithrilhall
08-02-04, 08:05 PM
It was nothing. I just forgot to post back.

T'was nothing but a simple mule.

Kambic
08-02-04, 11:46 PM
http://www.diabloii.net/characters/sorceress/screens/fire-wall-level1.jpg