I have Sygate Personal Firewall installed and often get messages that something is trying to send a message to or from my computer and will I let it happen.I normally say no.
I am surprised at the latest one as it seems to come from my own website-ftp.mysite.co.uk.
I will reproduce the *more details* packet below and wonder can anyone explain (thanks)
File Version : 4.90.0.3000
File Description : Win32 Kernel core component (kernel32.dll)
File Path : C:\WINDOWS\SYSTEM\kernel32.dll
Process ID : 0xFFCF58C7 (Heximal) 4291778759 (Decimal)
Connection origin : remote initiated
Protocol : TCP
Local Address : 194.165.181.48
Local Port : 3905
Remote Name : ftp.crocnaraw.co.uk
Remote Address : 212.187.158.5
Remote Port : 80
Ethernet packet details:
Ethernet II (Packet Length: 60)
Destination: 44-45-53-54-00-00
Source: 20-53-52-43-00-00
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 56
Protocol: 0x6 (TCP - Transmission Control Protocol)
Header checksum: 0x24be (Correct)
Source: 212.187.158.5
Destination: 194.165.181.48
Transmission Control Protocol (TCP)
Source port: 80
Destination port: 3905
Sequence number: 1928003676
Acknowledgment number: 234672623
Header length: 24
Flags:
0... .... = Congestion Window Reduce (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 0... = Push: Not set
.... .0.. = Reset: Not set
.... ..1. = Syn: Set
.... ...0 = Fin: Not set
Checksum: 0xba6a (Correct)
Data (0 Bytes)
Binary dump of the packet:
0000: 44 45 53 54 00 00 20 53 : 52 43 00 00 08 00 45 00 | DEST.. SRC....E.
0010: 00 2C 9A 10 40 00 38 06 : BE 24 D4 BB 9E 05 C2 A5 | .,..@.8..$......
0020: B5 30 00 50 0F 41 72 EB : 00 5C 0D FC D1 EF 60 12 | .0.P.Ar..\....`.
0030: E0 00 6A BA 00 00 02 04 : 05 B4 D4 3A | ..j........: