Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Other Topics > Networking > Stealth mode connection attempts...

Stealth mode connection attempts...
Thread Tools
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Oct 26, 2009, 12:15 PM
 
Running SL 10.6.1 w/firewall enabled and stealth mode on.

Console shows these types of messages (local IP changed to 999.999.9.99):

10/26/09 11:47:03 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:54071 from 208.67.222.222:53
10/26/09 11:49:04 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:56762 from 208.67.222.222:53
10/26/09 11:49:50 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:55559 from 208.67.222.222:53
10/26/09 11:51:11 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:50321 from 208.67.222.222:53
10/26/09 11:53:22 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:64826 from 208.67.222.222:53
10/26/09 11:53:26 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:64651 from 208.67.222.222:53
10/26/09 11:53:32 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:57787 from 208.67.222.222:53
10/26/09 11:53:36 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:60103 from 208.67.222.222:53
10/26/09 11:53:49 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:61517 from 208.67.222.222:53
10/26/09 11:56:11 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:50464 from 208.67.222.222:53
10/26/09 11:58:23 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:58148 from 208.67.220.220:53
10/26/09 11:59:57 AM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:54143 from 208.67.220.220:53
10/26/09 12:00:55 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:60148 from 208.67.220.220:53
10/26/09 12:04:05 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:52861 from 208.67.220.220:53
10/26/09 12:04:06 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:59358 from 208.67.220.220:53
10/26/09 12:04:06 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:54958 from 208.67.220.220:53
10/26/09 12:04:08 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:60569 from 208.67.220.220:53
10/26/09 12:04:09 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:54655 from 208.67.220.220:53
10/26/09 12:04:11 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:60542 from 208.67.220.220:53
10/26/09 12:04:12 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:63514 from 208.67.220.220:53
10/26/09 12:04:13 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:50930 from 208.67.220.220:53
10/26/09 12:05:05 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:62973 from 208.67.220.220:53
10/26/09 12:05:05 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:54111 from 208.67.220.220:53
10/26/09 12:05:22 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:62719 from 208.67.220.220:53
10/26/09 12:06:10 PM Firewall[63] Stealth Mode connection attempt to UDP 999.999.9.99:49868 from 208.67.220.220:53

Terminal WHOIS returns:


OrgName: OpenDNS, LLC
OrgID: OPEND-2
Address: 199 Fremont St.
Address: 12th Floor
City: San Francisco
StateProv: CA
PostalCode: 94105
Country: US

NetRange: 208.67.216.0 - 208.67.223.255
CIDR: 208.67.216.0/21
OriginAS: AS36692
NetName: OPENDNS-NET-1
NetHandle: NET-208-67-216-0-1
Parent: NET-208-0-0-0-0
NetType: Direct Assignment
NameServer: AUTH1.OPENDNS.COM
NameServer: AUTH2.OPENDNS.COM
NameServer: AUTH3.OPENDNS.COM
Comment:
RegDate: 2006-06-06
Updated: 2008-05-05

OrgAbuseHandle: GBP7-ARIN
OrgAbuseName: Patterson, George B
OrgAbusePhone: +1-415-344-3139
OrgAbuseEmail: abuse@opendns.com

OrgNOCHandle: GBP7-ARIN
OrgNOCName: Patterson, George B
OrgNOCPhone: +1-415-344-3139
OrgNOCEmail: abuse@opendns.com

OrgTechHandle: BF205-ARIN
OrgTechName: Fumerola, Bill
OrgTechPhone: +1-415-344-3145
OrgTechEmail: billf@opendns.com

# ARIN WHOIS database, last updated 2009-10-25 20:00
#


Should I be concerned?
Who is John Galt?
     
Moderator
Join Date: Jan 2001
Location: Brainstorming a geopolitical pivot
Status: Offline
Reply With Quote
Oct 26, 2009, 06:53 PM
 
do you use opendns? Does your network? OpenDNS is a well-known DNS service; their servers are quick and many people use them.

They are coming from port 53, which is the dns port, and it's using udp (normal) to an ephemeral port on your local machine. This is what it would look like in response to your computer browsing the internet.
     
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Oct 26, 2009, 08:55 PM
 
Originally Posted by Cold Warrior View Post
do you use opendns? Does your network? OpenDNS is a well-known DNS service; their servers are quick and many people use them.

They are coming from port 53, which is the dns port, and it's using udp (normal) to an ephemeral port on your local machine. This is what it would look like in response to your computer browsing the internet.


Yes, I guess I am using opendns. The console archived logs show that it's been going on for weeks, if not longer. I must have used the opendns servers because stupid U-verse servers were constantly returning errors when navigating the web.

I never noticed this before because it appears that since installing SL, the messages are much more numerous.

Thanks!
Who is John Galt?
     
Moderator
Join Date: Jan 2001
Location: Brainstorming a geopolitical pivot
Status: Offline
Reply With Quote
Oct 26, 2009, 09:12 PM
 
you started using it back in february.
http://forums.macnn.com/82/applicati...to-load-pages/
     
Mac Elite
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Oct 26, 2009, 09:20 PM
 
Originally Posted by cold warrior View Post
you started using it back in february.
http://forums.macnn.com/82/applicati...to-load-pages/
.
Who is John Galt?
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 12:00 PM.
All contents of these forums © 1995-2009 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.4 © 2000-2009, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2