Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Network UDP advice


  • Please log in to reply
10 replies to this topic

#1 Sunnybolero143

Sunnybolero143

  •  Avatar image
  • Members
  • 63 posts
  • OFFLINE
  •  
  • Local time:02:26 AM

Posted 26 August 2023 - 02:45 AM

Hi 

 

Hope some one can help me... not tech savvy on this sort of thing.  I recently suspected that maybe someone was accessing my Laptop. I installed TCP view

to try and look at what is being connected to my laptop.

 

i can see established connections  TCP  most using port 443...

 

i am unsure of what Listening means or if they cause a problem  and what UDP connections are... some posts suggest I should block UDP in my firewall, to be honest not sure what i do ... best not to tinker till i know what is best

 

attached is my current UDP connections , do these look ok?

Attached Files


Edited by hamluis, 26 August 2023 - 05:22 AM.
Moved from Firewall to Networking - Hamluis.


BC AdBot (Login to Remove)

 


#2 Sunnybolero143

Sunnybolero143
  • Topic Starter

  •  Avatar image
  • Members
  • 63 posts
  • OFFLINE
  •  
  • Local time:02:26 AM

Posted 26 August 2023 - 09:53 AM

Sorry seems was posted in the wrong forum, can anyone help me here?

 

kinda a newbie , so forgive me if i am asking the wrong people



#3 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:01:26 AM

Posted 26 August 2023 - 10:23 AM

The column on the far right in the image tells you what those are for.

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#4 Sunnybolero143

Sunnybolero143
  • Topic Starter

  •  Avatar image
  • Members
  • 63 posts
  • OFFLINE
  •  
  • Local time:02:26 AM

Posted 26 August 2023 - 10:24 AM

I now read the forum rules


Edited by Sunnybolero143, 27 August 2023 - 12:06 AM.


#5 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,188 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:09:26 PM

Posted 28 August 2023 - 11:58 PM

I don't see anything that stands out. Anyone else? Dan, you know more about this sort of thing.


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#6 Sunnybolero143

Sunnybolero143
  • Topic Starter

  •  Avatar image
  • Members
  • 63 posts
  • OFFLINE
  •  
  • Local time:02:26 AM

Posted 30 August 2023 - 05:39 AM

I really Now hope some can help me out here.

 

I noticed today that SSDPSrv had a coonection under UPD6v  Local address  144.173.22.110 for a University in England... This freaked me out See below.

 

I really do not understand what is UDP and what is UDP6v  , can someone explain what they are and what I should do.. I have real concern that someone as access to my laptop

 

..... I disabled service SSDPSrv  and also upnphost in service, although I am not sure what the impact will be

 

 

 


Edited by Sunnybolero143, 30 August 2023 - 05:42 AM.


#7 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:01:26 AM

Posted 30 August 2023 - 09:10 AM

UDP is a connectionless protocol and it is nit used in hacking. It is used in streaming because streaming you want uninterrupted TCP would interrupt the stream. UDPv6 is the ipv6 counterpart.

UPnP allows apps out of the firewall to connect. You can leave this one disabled as I do it.

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#8 Sunnybolero143

Sunnybolero143
  • Topic Starter

  •  Avatar image
  • Members
  • 63 posts
  • OFFLINE
  •  
  • Local time:02:26 AM

Posted 30 August 2023 - 11:04 AM

Cryptodan

 

Thanks for this... really a newbie.... kinda freaked out because I could not understand why this ip address is appearing on my local address when all others are showing my laptop name. been using TCPview to check my connections and to be truthful really should go and find a good tutorial on how these connections work

 

and yes i intend to keep UPnP disabled 

 

Ian



#9 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:01:26 AM

Posted 30 August 2023 - 11:25 AM

Just ask here I have a degree in computer Forensics and have pentesting experience.

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#10 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,188 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:09:26 PM

Posted 30 August 2023 - 12:38 PM

https://www.bleepingcomputer.com/startups/5174/ssdpsrv.exe/

 

SSDP Service is a completely normal part of Windows operations.

 

A word of advice: When my classmates and I first started psychology in university  and we learned about different psychological disorders, we were often convinced we had each consecutive one. Same thing is common with medical school newbies. And the same thing is common for people new to networking...they look at a few screens and see connections they don't understand and go into panic mode.

 

Only after you do a little learning and gain some experience will you likely be able recognize what's a legitimate connection and what isn't. And unless your PC is showing unusual behaviour, it's almost always nothing to worry about.

 

This is somewhat tangential, but if you're serious about learning basic "firewall forensics", this article is quite well-written:

http://www.capnet.state.tx.us/firewall-seen.html


Edited by Shplad, 30 August 2023 - 12:39 PM.

- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#11 svim

svim

  •  Avatar image
  • Members
  • 1,161 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:26 PM

Posted 30 August 2023 - 03:21 PM

UDP, and TCP for that matter, are both very common and essential networking protocols that have been in use for decades. Don't try to 'block it in your router', that will just intentionally create a big problem with your online access. Whomever suggested that to you was just trolling you with misinformation.

https://en.wikipedia.org/wiki/User_Datagram_Protocol#IPv4_pseudo_header






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users