Jump to content

kerio connections


raptors892004

Recommended Posts

I installed the free kerio firewall yesterday (still in trial mode for now) and I've been getting those connections to the Kerio GUI program a couple of times during the day now.. I just wondered what they are.. Attached is a screenshot of the log showing those connections :)

EDIT: Those shown connection attempts are like 2-3 secs apart from each other.. There were numerous connections such as those at 9am and now those 2 secs apart (about 20 of them) were at 3pm.. I may have to swtich firewalls, don't I? :(

EDIT2: All of those connections are targeted towards port 1027 on my pc.. Is that for windows component or something?

Link to comment
Share on other sites

The morning IPs were from those Asia Network center as well and no, no p2p running.. Just F@H client and pogo.com :).. I posted here in case this was an exploit attempt or something.. I also had AVG free running but I disabled automatic updating before so I know its not checking or anything.. Hope anyone helps :)

Link to comment
Share on other sites

Port 1027 can also be associated with ICKiller Trojan....Run a security scan, and see what you get...

https://www.grc.com/x/ne.dll?bh0bkyd2 --Try that scan..Click on proceed, and find All Service Ports, and click that..

http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym --Or try the Symantec scan..

Just for reference, my pc is completely stealth, and I am in my DMZ...If you have open ports, you may want to investigate further...

Link to comment
Share on other sites

I have no reason to have that trojan.. No p2p or malware installed on my pc guaranteed.. I have spyware blaster, ad-aware, spybot and AVG running plus I don't visit those scam (unsafe) sites, so I'm pretty sure no trojan is in my system.. I'll run an AVG scan anyways, but I doubt if it finds anything.. I blocked port 1025 in my firewall also and all my service ports were stealth :)

Link to comment
Share on other sites

also my connections read 4 in and 4 out with nothing connected and mine does not do that so something is not right with yours.  to stop that goto network settings and put an x on all kerio personal firewall  and when you update which wont be many more cause its being dis-continued  just switch to another firewall.  anyway here is my connections  just sitting on the net.

Link to comment
Share on other sites

also my connections read 4 in and 4 out with nothing connected and mine does not do that so something is not right with yours.  to stop that goto network settings and put an x on all kerio personal firewall  and when you update which wont be many more cause its being dis-continued  just switch to another firewall.  anyway here is my connections  just sitting on the net.

You have those ports open that I disabled access to (1029, 1028, 1027).. You can see Kerio GUI is listening at them in your pic.. That is what my concern was (about those service ports)..  Visit https://www.grc.com/x/ne.dll?bh0bkyd2 to test your service ports and see what you have open (click on the link, then proceed, then service ports to test) :)

Link to comment
Share on other sites

i passed all the tests there and every port was stealth

Stealth is the way to be.....Can't attack what you can't see...

That test only does the first 1056, but is still a good test...

Try these..

http://scan.sygate.com/prequickscan.html  -quick scan

http://scan.sygate.com/prestealthscan.html -stealth scan

http://scan.sygate.com/pretrojanscan.html -Trojan port scan

http://scan.sygate.com/pretcpscan.html -TCP port scan

http://scan.sygate.com/preudpscan.html -UDP port scan

:D

Link to comment
Share on other sites

Tested using XP's FireWall:

FILE SHARING

YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.

COMMON PORTS

Your system has achieved a perfect "TruStealth" rating. Not a single packet

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...