Security Basics mailing list archives

multicast connection trials from a home machine - is it regular?


From: "ruben" <rubenb () arnet com ar>
Date: Tue, 15 Apr 2003 11:46:51 -0300

From the firewall log:
"blocked: Out ICMP;Router solicitation;localhost->224.0.0.2;Owner: Tcpip
Kernel Driver"
That is done (as the first outbound communication) every time the machine is
connected via dialup to the Internet. Is that a logical part of the process?
OS is Win98, firewall is Kerio, the rule CAN be modified, but the blocking
came as default in the firewall settings. What arises my doubts is that the
firewall blocks the attempt to connect to 224.0.0.2 but the http and mail
service go back and forth as usual. A short Google search shows some info
about multicast in NT machines, but nothing worthwile. I'm suspecting of
some backdoor sitting in this machine. Of course it can be a part of a
legitimate process. Can you enlighten me about this?
TIA, Ruben.-


-------------------------------------------------------------------
Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the 
world's premier event for IT and network security experts.  The two-day 
Training features 6 hand-on courses on May 12-13 taught by professionals.  
The two-day Briefings on May 14-15 features 24 top speakers with no vendor 
sales pitches.  Deadline for the best rates is April 25.  Register today to 
ensure your place.  www.blackhat.com
-------------------------------------------------------------------


Current thread: