• RSS
  • Twitter
  • FaceBook

Security Forums

Log in

FAQ | Search | Usergroups | Profile | Register | RSS | Posting Guidelines | Recent Posts

Is this normal or am I being hacked???

Users browsing this topic:0 Security Fans, 0 Stealth Security Fans
Registered Security Fans: None
Post new topic   Reply to topic   Printer-friendly version    Networking/Security Forums Index -> Anonymity // Privacy // Spam

View previous topic :: View next topic  
Author Message
nub2security
Just Arrived
Just Arrived


Joined: 30 Apr 2007
Posts: 0
Location: Montreal

Offline

PostPosted: Tue May 22, 2007 6:52 pm    Post subject: Is this normal or am I being hacked??? Reply with quote

Hi:

I'm getting these firewall reports in my event log:

#1:

Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/22/2007
Time: 11:37:19 AM
User: ***********
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

Name: FIREFOX
Path: C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.exe
Process identifier: 2664
User account: *****
User domain: NT AUTHORITY
Service: NO
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 2858
Allowed: YES
User notified: No

This pattern continues many *28 times* until I see
#2

Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/22/2007
Time: 11:45:21 PM
User: NT AUTHORITY\SYSTEM
Description:
The Windows Firewall has detected an application listening for incoming traffic.

it appears using UDP protocol for the following ports,
#3477, 3479, 3465, 3477, 3467 3463, 3461, 3457, 3455, 3453, etc...
events are one right after the other in my security log

NOTE: I use Tor.

Is this normal or do I have issues or something that should not be happening here? Or am I being overly paranoid.

Thank you,
Any help is welcomed!
nub2security
Back to top
View user's profile Send private message
Dan.M
Trusted SF Member
Trusted SF Member


Joined: 14 Feb 2007
Posts: 0
Location: Jacksonville, FL USA

Offline

PostPosted: Sun Sep 16, 2007 5:15 am    Post subject: Reply with quote

I suspect that it is merely detecting Tor. Have you set it up to also relay traffic for peers? If so, then that is what is going on.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   

Post new topic   Reply to topic   Printer-friendly version    Networking/Security Forums Index -> Anonymity // Privacy // Spam All times are GMT + 2 Hours
Page 1 of 1


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Community Area

Log in | Register