I was having some trouble with my computer at about the time I saw the following on my Firewall Log:
1:34:54 PM SYSTEM: 4 IP bind to * Allow rawsocket connection
Can somebody tell me what this means?
Hello purrcy,
On Windows 2000, XP and VISTA, raw sockets are enabled by default. Although Outpost can protect your system from raw socket abuse (it should prompt you if anything accesses them), it is more secure to disable raw sockets completely. I have raw sockets disabled on both my XP and VISTA systems. Keeping raw sockets enabled can make your system vulnerable to malware attacks and should be immediately disabled - it is very unlikely that most users need them enabled in the first place.
Steve Gibson's Freeware Listing (http://www.grc.com/freepopular.htm) contains many excellent utilities to help lock down your system. In this case, you need to download and execute "SocketLock" and "Socket To Me". I would also do a thorough malware scan of your system since it looks as though something has tried to access your systems raw sockets. In OPF 4.0, Outpost should have alerted you to anything that needed access. Im not using 2008 but presumably a similar function is also in there.
purrcy,
A new thread (http://outpostfirewall.com/forum/showthread.php?t=22524) has been created re keyboard and mouse locked out and another (http://outpostfirewall.com/forum/showthread.php?t=22525) re spoolsv.exe.
In OFP 2008 v. 2225, I also -still- see this entry in the firewall log
6:31:03 SYSTEM: 4 IP bind to * Allow rawsocket connection
and this one under Used Ports
IP local address is: local:any local port is: n/a
What is system: 4? I have rawsockets access blocked via the options tab in most of my apps rules (svchost, acs and op_mon in particular).
I have asked before about this and filed a ticket last October. I guess I will file a ticket again.
purrcy,
I suggest you contact Agnitum directly:
http://www.agnitum.com/support/forms/submitabug.php
This is what shows in my Open Ports Viewer using OPF 4.0 with raw sockets disabled system-wide.
I could use some help again...
Lost Licences |