DarkestDream Posted December 20, 2005 Report Share Posted December 20, 2005 My Sygate shut down the internet access because IANA keep pinging on me. so i am not sure what is going on. I backtrace the ip address and found out that IANA is doing this. it pinging on two apps, NT Kernel & System and NDIS User mode I/O Driver and it sending info to IANA too. so i created a advanced rule to block that ip address, it did but it still pinging on two apps. so i told the rule to dont allow those access to two apps. and it blocking it. So i ask it to make a packet log of it. amazing, it pinging on me every two min, but it blocked already. it all incoming. one outgoing from NDIS USer Mode I/O Driver.Why IANA is doing this? Quote Link to post Share on other sites
MrBill Posted December 20, 2005 Report Share Posted December 20, 2005 My Sygate shut down the internet access because IANA keep pinging on me. so i am not sure what is going on. I backtrace the ip address and found out that IANA is doing this. it pinging on two apps, NT Kernel & System and NDIS User mode I/O Driver and it sending info to IANA too. so i created a advanced rule to block that ip address, it did but it still pinging on two apps. so i told the rule to dont allow those access to two apps. and it blocking it. So i ask it to make a packet log of it. amazing, it pinging on me every two min, but it blocked already. it all incoming. one outgoing from NDIS USer Mode I/O Driver.Why IANA is doing this?Internet Assigned Numbers AuthorityDo you have a web page that you maintain?IANA Quote Link to post Share on other sites
DarkestDream Posted December 20, 2005 Author Report Share Posted December 20, 2005 i have no web page at all Quote Link to post Share on other sites
CataclysmCow Posted December 30, 2005 Report Share Posted December 30, 2005 The IANA isn't pinging you. It's hard to tell from your post, but it sounds like your machine is responding to a machine pinging you on your network. IANA is assigned the CIDR block 192.0.0.0/17. What is the address that's pinging you?It's much more likely that you are dealing with a private block address. If you do a whois on one of these addresses it'll come up as registered to IANA. The private blocks are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.Could you provide logs of the traffic? Quote Link to post Share on other sites
DarkestDream Posted December 30, 2005 Author Report Share Posted December 30, 2005 I planned to put a full log but it really log, i start packet log for that ip address. IF you want a full log, i can email you. the file is over 800KB. so here the short version of the log i cut the most out. this log show the most recent and it all the same. 117609 12/29/2005 17:32:11 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\ntoskrnl.exe 117610 12/29/2005 17:38:12 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\DRIVERS\ndisuio.sys 117611 12/29/2005 17:38:12 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\ntoskrnl.exe 117612 12/29/2005 17:47:11 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\DRIVERS\ndisuio.sys 117613 12/29/2005 17:47:11 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\ntoskrnl.exe 117614 12/29/2005 17:50:11 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\DRIVERS\ndisuio.sys 117615 12/29/2005 17:50:11 192.168.1.102 138 192.168.1.255 138 Incoming Blocked C:\WINDOWS\system32\ntoskrnl.exe 117616 12/29/2005 17:52:16 192.168.1.102 137 192.168.1.255 137 Incoming Blocked C:\WINDOWS\system32\DRIVERS\ndisuio.sys 117617 12/29/2005 17:52:16 192.168.1.102 137 192.168.1.255 137 Incoming Blocked C:\WINDOWS\system32\ntoskrnl.exe Quote Link to post Share on other sites
isteve Posted December 30, 2005 Report Share Posted December 30, 2005 The pings are coming from your local area network not the internet. Are you on a wireless network? Quote Link to post Share on other sites
DarkestDream Posted December 30, 2005 Author Report Share Posted December 30, 2005 yea, but it pinging started couple week ago. i on wireless for two years and why now?? why not two years ago? Quote Link to post Share on other sites
iccaros Posted December 30, 2005 Report Share Posted December 30, 2005 is your wireless encrypted..??also can you do a tcp dump (ethereal is a good tool for this) and post it.. this will let us see the traffic on the system (no need to worry about IP's as you look to be running a 192.168.1.0/24 network) adn just beacuse you have had wireless for two years does not mean some one did not get in yesterday Quote Link to post Share on other sites
DarkestDream Posted December 30, 2005 Author Report Share Posted December 30, 2005 i have ethereal, but how i do TCP Dump with ethereal Quote Link to post Share on other sites
iccaros Posted December 30, 2005 Report Share Posted December 30, 2005 sorry TCP DUMP is a unix tool, and like google has been verbizes... Ethereal uses the tcp dump code.. do a capture of traffic adn post if.. and keep the capture as we may ask to see some packages expanded. I'm guessing your seeing a lot of master browser elections.. but I can's tell if I am not on the system. Quote Link to post Share on other sites
DarkestDream Posted December 30, 2005 Author Report Share Posted December 30, 2005 i tried to upload the attachment of my tcp dump log but the forum wont accept non-extension. it need a extension for it to upload. so which kind of format should i save it as? cant use libpcap cuz it save without extension Quote Link to post Share on other sites
iccaros Posted December 31, 2005 Report Share Posted December 31, 2005 ??? txt Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 here the log... Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 i stop the capture after it reach 50 KB which it about 14 sec. i have the log packet details as displayedHere the file my_tcp_file.txt Quote Link to post Share on other sites
iccaros Posted December 31, 2005 Report Share Posted December 31, 2005 what is your address? I'll bet money its 192.168.1.102do you have gnutella installed? Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 (edited) I use gnutella long time ago like two years ago, and stop using it two years ago after founding out that it illegal to share and download the copyright fileAnd already uninstall it two years ago too, i already check my system to make sure no trace of p2p program. the only program i use is LimeWire that time.That not my address, that is IANA. that the address i blocked in my advanced rule in Sygate. here what WHOIS saidNetRange: 192.168.0.0 - 192.168.255.255 CIDR: 192.168.0.0/16 NetName: IANA-CBLK1NetHandle: NET-192-168-0-0-1Parent: NET-192-0-0-0-0NetType: IANA Special UseNameServer: BLACKHOLE-1.IANA.ORGNameServer: BLACKHOLE-2.IANA.ORGComment: This block is reserved for special purposes.Comment: Please see RFC 1918 for additional information.Comment: RegDate: 1994-03-15Updated: 2002-09-16OrgAbuseHandle: IANA-IP-ARINOrgAbuseName: Internet Corporation for Assigned Names and Number OrgAbusePhone: +1-310-301-5820OrgAbuseEmail: [email protected]OrgTechHandle: IANA-IP-ARINOrgTechName: Internet Corporation for Assigned Names and Number OrgTechPhone: +1-310-301-5820OrgTechEmail: [email protected]# ARIN WHOIS database, last updated 2005-12-30 19:10# Enter ? for additional hints on searching ARIN's WHOIS database. Edited December 31, 2005 by DarkestDream Quote Link to post Share on other sites
iccaros Posted December 31, 2005 Report Share Posted December 31, 2005 ok tcp/ip lession..no one from a privet address (aka unroutable) like 192.168.*.* can ping you from out side your network. It can't route.. its impossable. please read up on tcp/ip cider http://searchnetworking.techtarget.com/sDe...i213850,00.htmland in this case udp port 2335 (p2p software ports) you have gnutilla running on the system.go to run typecmdtype ipconfig /allcut and past and post all output of the command.also looking at the logs.. I'll break this down..you are on a switched port meaning you can only see what is being sent to and from your..here is one packetEthernet II, Src: LinksysG_77:ed:6f (00:06:25:77:ed:6f), Dst: LinksysG_5f:9b:20 (00:0c:41:5f:9b:20)Internet Protocol, Src: 68.115.142.126 (68.115.142.126), Dst: 192.168.1.102 (192.168.1.102)Transmission Control Protocol, Src Port: 33056 (33056), Dst Port: 1550 (1550), Seq: 0, Ack: 0, Len: 37Data (37 bytes)address 68.115.142.126 is a internet address.... not one of your computers..address 192.168.1.102 has to be you.... its the only way you could see traffic from 68.115.142.126 to 68.115.142.126. There is no other way.. Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 Windows IP Configuration Host Name . . . . . . . . . . . . : Darkest_Dream Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Broadcast IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : crlsca.adelphia.netEthernet adapter Dark Messenger: Connection-specific DNS Suffix . : crlsca.adelphia.net Description . . . . . . . . . . . : Wireless-G PCI Adapter Physical Address. . . . . . . . . : 00-0C-41-60-B1-AB Dhcp Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IP Address. . . . . . . . . . . . : 192.168.1.100 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.1.1 DHCP Server . . . . . . . . . . . : 192.168.1.1 DNS Servers . . . . . . . . . . . : 67.21.13.7 67.21.13.6 Lease Obtained. . . . . . . . . . : Saturday, December 31, 2005 9:41:42AM Lease Expires . . . . . . . . . . : Sunday, January 01, 2006 9:41:42 AM Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 for some reason, i cant release my ip address, it asked me to specify which adapter, i type downipconfig /release Wireless-G PCI Adapterso it said it wrong so then i typeipconfig /release Dark Messengerand it still not releasing, it just said it wrong. even i try without the name and it still need a network name Quote Link to post Share on other sites
TheTerrorist_75 Posted December 31, 2005 Report Share Posted December 31, 2005 Just use ipconfig to see what the adapter name is.Ipconfig WinXP Quote Link to post Share on other sites
DarkestDream Posted December 31, 2005 Author Report Share Posted December 31, 2005 (edited) Windows IP ConfigurationThe operation failed as no adapter is in the state permissible forthis operation.it didnt like me Edited December 31, 2005 by DarkestDream Quote Link to post Share on other sites
DarkestDream Posted January 2, 2006 Author Report Share Posted January 2, 2006 look like it stop. i just check the packet log yesterday and today, nothing it pinging on me. that a good thing but let see later, hoping it stop Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.