Computing.Net > Forums > Security and Virus > Message from Sygate Firewall

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Message from Sygate Firewall

Reply to Message Icon

Original Message
Name: geordief
Date: November 23, 2005 at 04:51:01 Pacific
Subject: Message from Sygate Firewall
OS: me
CPU/Ram: 300mhz/256 memorry
Comment:

I have Sygate Personal Firewall installed and often get messages that something is trying to send a message to or from my computer and will I let it happen.I normally say no.
I am surprised at the latest one as it seems to come from my own website-ftp.mysite.co.uk.
I will reproduce the *more details* packet below and wonder can anyone explain (thanks)

File Version : 4.90.0.3000
File Description : Win32 Kernel core component (kernel32.dll)
File Path : C:\WINDOWS\SYSTEM\kernel32.dll
Process ID : 0xFFCF58C7 (Heximal) 4291778759 (Decimal)

Connection origin : remote initiated
Protocol : TCP
Local Address : 194.165.181.48
Local Port : 3905
Remote Name : ftp.crocnaraw.co.uk
Remote Address : 212.187.158.5
Remote Port : 80

Ethernet packet details:
Ethernet II (Packet Length: 60)
Destination: 44-45-53-54-00-00
Source: 20-53-52-43-00-00
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 56
Protocol: 0x6 (TCP - Transmission Control Protocol)
Header checksum: 0x24be (Correct)
Source: 212.187.158.5
Destination: 194.165.181.48
Transmission Control Protocol (TCP)
Source port: 80
Destination port: 3905
Sequence number: 1928003676
Acknowledgment number: 234672623
Header length: 24
Flags:
0... .... = Congestion Window Reduce (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 0... = Push: Not set
.... .0.. = Reset: Not set
.... ..1. = Syn: Set
.... ...0 = Fin: Not set
Checksum: 0xba6a (Correct)
Data (0 Bytes)

Binary dump of the packet:
0000: 44 45 53 54 00 00 20 53 : 52 43 00 00 08 00 45 00 | DEST.. SRC....E.
0010: 00 2C 9A 10 40 00 38 06 : BE 24 D4 BB 9E 05 C2 A5 | .,..@.8..$......
0020: B5 30 00 50 0F 41 72 EB : 00 5C 0D FC D1 EF 60 12 | .0.P.Ar..\....`.
0030: E0 00 6A BA 00 00 02 04 : 05 B4 D4 3A | ..j........:


Report Offensive Message For Removal








Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Message from Sygate Firewall

Sygate and ntoskrnl.exe
    Summary: newgate, to get rid of the pop-up.In sygate go to tools/options/general.. check the box "hide notification messages". From Sygate: Question: Why does the notification box keep showing up after checki...
www.computing.net/answers/security/sygate-and-ntoskrnlexe/17014.html

Sygate Firewall Pro
    Summary: I am using Sygate firewall (non pro) and I am unable to send large attachments through sygate. I am running win xp home and sygate needs outlook, nwlink ipx spx protocol driver and ndis usermode i/o...
www.computing.net/answers/security/sygate-firewall-pro/3862.html

Sygate Firewall & ICMP
    Summary: Who's your ISP? I may be wrong here and someone may corect me but, for example, I have AT&T/Bellsouth as my ISP. AT&T has its own firewall on its servers and all my traffic routes through that. I ha...
www.computing.net/answers/security/sygate-firewall-amp-icmp/21942.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software