Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Ok, what the heck does it mean when someone "pings" your firewall?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
foxglove1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 10:07 PM
Original message
Ok, what the heck does it mean when someone "pings" your firewall?
I've been getting LOTS of ping alerts on my Zonealarm the past 4 days and it's driving me nuts. Yesterday I had about 219 in a 4 hour period

The firewall has blocked Internet access to your computer (ICMP Echo Request ('Ping')) from 172.170.124.43

Anyone good at tracking down these IP numbers? I've had 11 alerts in the past 6 minutes. Here are the numbers:

172.162.47.29
211.163.117.132
61.243.45.11
172.167.196.54
68.155.2.172
172.164.188.118
172.158.9.170
172.170.124.43
12.169.122.244
172.167.250.141
172.166.8.226

Sue

Printer Friendly | Permalink |  | Top
Nlighten1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 10:10 PM
Response to Original message
1. Do you play any online games?
I have noticed this sort of traffic from the games I play but it really could be anything. A ping is a tool you use to see if there is a host at the address you ping.
Printer Friendly | Permalink |  | Top
 
foxglove1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 10:13 PM
Response to Reply #1
2. Nope, it starts about 1-2 minutes after I sign onto AOL
But it's only been for the past 4 days. Maybe once in a great while before that, but since Wednesday, it's just a constant steady stream from the time I sign on to the moment I sign off

Sue
Printer Friendly | Permalink |  | Top
 
punpirate Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 10:26 PM
Response to Reply #2
4. "Ping" is a simple request...
... from one computer to another on a network, asking, in essence, "who are you and is this your correct IP address."

Sometimes, this can be a request from your provider's host, to see if you're still on-line, because, otherwise, if there's some other error, it would like to close the connection.

But, for the most part, it's a hostile computer looking to see, first, if there's a running computer at a particular IP address. If there is, and that computer returns a ping, then the port scanner gets turned on, looking for an available port which might gain them access to your computer.

ZoneAlarm, set up properly, will not answer pings. That's intended to make the remote computer keep trying to hit yours until it gives up--making your computer seem to be not there or turned off, and that way, to deter someone taking the time to scan for available ports.

It's a reasonably good first line of defense.

But, PING is just a standard network command to establish the existence of a computer at a particular net address. I get several hundred every few days.

To check on IP addresses yourself, just get yourself a copy of Sam Spade or Net Demon and have at. ;-)


Cheers.
Printer Friendly | Permalink |  | Top
 
Philosophy Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 10:25 PM
Response to Original message
3. Try here
Printer Friendly | Permalink |  | Top
 
scipan Donating Member (374 posts) Send PM | Profile | Ignore Sat Aug-23-03 10:55 PM
Response to Original message
5. I've been getting a lot of pings lately too
about 6-8 per minute. It's very unusual. I figured it had to do with the viruses out there.

When I had Napster, we would ping each other all the time, to see how long a round trip took. If it was pretty short, that was a good person to download from.
Printer Friendly | Permalink |  | Top
 
TreasonousBastard Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-23-03 11:20 PM
Response to Original message
6. Do you have an AOL account?
Most of those are AOL pings, and would be normal. The Chinese spammer might not be, but could be just background traffic. There is a vast amount of background traffic out there, and only rarely is someone actually attacking your machine.

Turn the alerts off-- they are real PITA.

If you want to know who owns the IP's:

http://www.iks-jena.de/cgi-bin/whois

The page is in German, but it's obvious how it works, and the returns are in English.

If you want to know more, find out how to work traceroute, Sam Spade, and other tools.

(serious geek stuff there, though)

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 12:56 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC