interesting alerts on Zonealarm recently - what do I do?

interesting alerts on Zonealarm recently - what do I do?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
interesting alerts on Zonealarm recently - what do I do? Paul 11-27-2006
Posted by Paul on November 27, 2006, 7:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My son came home from college using his laptop on my network with a Netgear
router. Now I regularly get this alert:

"ZoneAlarm blocked traffic to port 2869 on your machine from port 1077 on a
remote computer whose IP address is 192.168.1.1. This communication attempt
may have been a port scan, or simply one of the millions of unsolicited
commercial or network control messages that are routinely sent out over the
Internet. Such unsolicited messages are often called Internet background
noise."

It's being stopped which is good but 192.168.1.1 is my router's address.

What do I do?



Posted by jon on November 27, 2006, 7:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Paul wrote:

>What do I do?

Turn off alerts.

Posted by Slarty on November 27, 2006, 7:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Mon, 27 Nov 2006 19:26:10 -0500, Paul wrote:

> My son came home from college using his laptop on my network with a Netgear
> router. Now I regularly get this alert:
>
> "ZoneAlarm blocked traffic to port 2869 on your machine from port 1077 on a
> remote computer whose IP address is 192.168.1.1. This communication attempt
> may have been a port scan, or simply one of the millions of unsolicited
> commercial or network control messages that are routinely sent out over the
> Internet. Such unsolicited messages are often called Internet background
> noise."
>
> It's being stopped which is good but 192.168.1.1 is my router's address.
>
> What do I do?

Remove ZoneAlarm, of course.

Posted by Ansgar -59cobalt- Wiechers on November 27, 2006, 7:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> My son came home from college using his laptop on my network with a
> Netgear router. Now I regularly get this alert:
>
> "ZoneAlarm blocked traffic to port 2869 on your machine from port 1077
> on a remote computer whose IP address is 192.168.1.1. This
> communication attempt may have been a port scan, or simply one of the
> millions of unsolicited commercial or network control messages that
> are routinely sent out over the Internet. Such unsolicited messages
> are often called Internet background noise."
>
> It's being stopped which is good but 192.168.1.1 is my router's
> address.
>
> What do I do?

Inspect the traffic with a sniffer (e.g. Wireshark [1]) to find out
what's the payload of these packets. It should suffice if you install
the sniffer on the same machine ZA is installed on, but in case it
doesn't you have to tap the wire.

Also check the configuration of your router. Any port-forwardings? Is
the firmware up-to-date? Run a portscan against the router (from the
outside) to check if there are any ports open on the external interface.
Netgear routers have become infamous for being vulnerable.

[1] http://www.wireshark.org/

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Posted by Mr. Arnold5 on November 28, 2006, 1:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Paul wrote:
> My son came home from college using his laptop on my network with a Netgear
> router. Now I regularly get this alert:
>
> "ZoneAlarm blocked traffic to port 2869 on your machine from port 1077 on a
> remote computer whose IP address is 192.168.1.1. This communication attempt
> may have been a port scan, or simply one of the millions of unsolicited
> commercial or network control messages that are routinely sent out over the
> Internet. Such unsolicited messages are often called Internet background
> noise."
>
> It's being stopped which is good but 192.168.1.1 is my router's address.
>
> What do I do?
>
>

You tell ZA to trust the Device IP of the router. The router iss doing
the scanning, which is harmless. It's either that or remove ZA from the
machine.

Duane :)

Similar ThreadsPosted
Strange ZoneAlarm Alerts July 4, 2006, 7:16 pm
Interesting URL for Firewalls August 5, 2004, 4:19 pm
Interesting Problem with Checkpoint Secure platform and Nortel VOIP May 16, 2007, 11:14 am
Kerio 4.3 alerts January 14, 2007, 1:22 pm
Zone Alarm Alerts September 4, 2005, 1:33 am
Now getting TWO alerts from ZA when I open my browser January 14, 2006, 10:42 am
Norton Personal Firewall Alerts December 16, 2004, 6:16 pm
Norton Internet Security Alerts November 28, 2005, 7:32 am
Norton Internet Security Alerts November 28, 2005, 7:35 am
Norton Internet Security Intrusion Detection Alerts November 10, 2005, 8:14 pm

The site map in XML format XML site map

Contact Us | Privacy Policy