Jump to content
Claris Engage 2025 - March 25-26 Austin Texas ×

This topic is 3974 days old. Please don't post here. Open a new topic instead.

Recommended Posts

Posted

Hi:

 

I was checking my Kapersky settings on the computer hosting fmserver, and found it is sending TCP info to 2 IP addresses in Ukraine:

176.32.99.193:443 and 176.32.99.56:443

I blocked those addresses and then fmserver.exe connected again to Ukraine through other addresses.

 

Amounts of data are small (largest 9 KB received/1.6 KB sent) all active for many hours.

It is also receiving small amounts of data on connections open for many days through its LAN address (192.168.1.5), using ports 49204 and 49163.

 

As soon as I turned off the server, all traffic vanished except for an inbound under Java Platform SE binary (23.202.103.219:443) which belongs to Akamai

And what seems to be an intermitent ping under the same Java from 127.0.0.1:50003

 

Any ideas of what this is?

 

Extra info:

None of the above mentioned ports appear as open on Kapersky's listing.

Server v 11.0.5.510

I use 360 Works Safetynet back up.

Kapersky Internet Security

Acer Travel Mate 4740-5755 Intel core i3-500M processor, 4GB RAM

Windows 7 Pro.

Java 7:25

Ports open on router for FM server are 5003, 50003 and 50006

8080 for Supercontainer on Tomcat

 

Thanks

Carlos

Posted

UPDATE

It was  360 Works Safety net, I disabled the plugin, and the connections stopped, re-enabled it, and they started again.

Wow, I did get scared!

 

Carlos

This topic is 3974 days old. Please don't post here. Open a new topic instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.