Zone Alarm Q

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
Jim
SG VIP
Posts: 13229
Joined: Mon Oct 16, 2000 12:00 am

Zone Alarm Q

Post by Jim »

When Zone Alarm says something like "it has blocked acces to your computer from xxx.xxx.xxx.xxx, what exactly does this mean? A WHOIS check usually reveals that its someone on a RoadRunner connection. What exactly does this mean though? Someone with RoadRunner as their ISP was trying to get in? Scanning my ports? ? :confused:
User avatar
Roody
SG VIP
Posts: 30735
Joined: Sun Nov 19, 2000 12:00 am
Location: East Tennessee

Post by Roody »

Originally posted by BIGJIMSLATE:
When Zone Alarm says something like "it has blocked acces to your computer from xxx.xxx.xxx.xxx, what exactly does this mean? A WHOIS check usually reveals that its someone on a RoadRunner connection. What exactly does this mean though? Someone with RoadRunner as their ISP was trying to get in? Scanning my ports? ? :confused:

well its possible that if RR is your provider that they may be pinging you as routine. i would monitor the ip and see how much it happens. if you are worried about it you can always go ahead and call RR and ask them if that pinging is coming from them. Sorry i wasnt more helpful.
User avatar
Jim
SG VIP
Posts: 13229
Joined: Mon Oct 16, 2000 12:00 am

Post by Jim »

No, I'm on Adelphia's cable networks. And its not ALWAYS Road Runner, but I'd say about half of the ip's go back there.

It doesn't happen TOO often, but at least once a week where Zone Alarm will say it blocked access.
User avatar
Silver
Posts: 3311
Joined: Sun Nov 05, 2000 12:00 am
Location: Somewhere drinking like its going out of style.

Post by Silver »

Wouldn't worrie too much jim. Alot of that are just random scans I believe. Normally what to look for are mass attacks, such as 5-more warnings from the same ip on different ports, that would basically be someone scanning you. As far as warnings, I get about 10-15 a day. Just random stuff though. I pay attention to the ones that hit me hard. Like on irc one day, there was a guy in one of the channels that i goto that had a script that upon joining the channel would hit you 18 times. He didnt even know it wasd doing it. Freaked me out though. hehe, so random scans i wouldnt worrie about. When ever you pull up Zone and you have like 32 alerts, from the same ip, thats when i would worrie.
User avatar
Scoot
Regular Member
Posts: 449
Joined: Sun Oct 22, 2000 12:00 am
Location: Spokane WA. USA

Post by Scoot »

You can learn what those alerts are telling you by reading Robert Graham's :
FAQ: Firewall Forensics (What am I seeing?)
User avatar
lewis
Regular Member
Posts: 480
Joined: Thu Feb 03, 2000 12:00 am
Location: Canada

Post by lewis »

A really sweet program that breaks down and explains what the ZA alerts means is called Zonelog. It is a separate program than ZA. Get it here

You just import the ZA logs into it and it'll tell you pretty much everything.

(originally posted by 'Norm' @ Speedcorp)

[ 03-20-2001: Message edited by: lewis ]
quiet sound
New Member
Posts: 18
Joined: Sun Mar 18, 2001 12:00 am

Post by quiet sound »

Not too long ago ZA (not Pro version) stopped writing to the log file. It's there, the name is correct and the box in ZA is checked for sending the alerts to the log, it just doesnt do it anymore. Any ideas?
Post Reply