• February 23, 2025, 11:00:39 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Internet access  (Read 7777 times)

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Internet access
« on: December 04, 2012, 11:44:32 AM »

Hi all,
does anyone know why DNS-323 (firmware 1.10) is trying to connect to the following addresses:
205.171.76.135:8245
61.67.210.241:8245
168.158.8.115:80

I use this box for backup only and don't have any service enabled (no UPnP, no iTunes, no DHCP, no LLTD and not even NTP). I see no reason to connect outside my local network but it still does. I disabled internet access in my router (DIR-655) and it reports the following:
Internet access port filter dropped packet from 192.168.0.X:2261[DN:S3:23:AD:DR] to 168.158.8.115:80 (protocol 6)
Internet access port filter dropped packet from 192.168.0.X:2364[DN:S3:23:AD:DR] to 61.67.210.241:8245 (protocol 6)
Internet access port filter dropped packet from 192.168.0.X:2078[DN:S3:23:AD:DR] to 205.171.76.135:8245 (protocol 6)

Thanks,
d323bkpuser
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Internet access
« Reply #1 on: December 04, 2012, 11:57:37 AM »

Domain Tools is reporting that the 1st ip adderss belongs to DLink, the 2nd address belongs to some Taiwan Taipei Koos Broadband Telecom Co. Ltd in Taiwan and the 3rd belongs to Sprint.



Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Re: Internet access
« Reply #2 on: December 04, 2012, 12:03:32 PM »

None of them makes sense. DLink on port 8245? At first I thought is NTP to blame, but that's on port 123 and as I said is disabled. Why would it try to connect to all these addresses / ports.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Internet access
« Reply #3 on: December 04, 2012, 12:39:36 PM »

Not sure, if there are any services on the DNS and needs this or not. I would phone contact DLink support, level 2 and higher and inquire about this.

Have you tried blocking these addresses on your host router and what are the results, if any?

Let us know what they say.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Re: Internet access
« Reply #4 on: December 04, 2012, 12:52:41 PM »

Yes, I blocked all access to outside from DNS-323 MAC address. I posted what DIR-655 reports in my initial post. Here they are again:

Code: [Select]
[INFO] Tue Dec 04 13:29:18 2012 Dropped packet from 192.168.0.X to 168.158.8.115 (IP protocol 6) as unable to create new session
[INFO] Tue Dec 04 13:29:18 2012 Internet access port filter dropped packet from 192.168.0.X:2261[DN:S3:23:AD:DR] to 168.158.8.115:80 (protocol 6)
....
[INFO] Tue Dec 04 13:28:14 2012 Dropped packet from 192.168.0.X to 61.67.210.241 (IP protocol 6) as unable to create new session
[INFO] Tue Dec 04 13:28:14 2012 Internet access port filter dropped packet from 192.168.0.X:2364 [DN:S3:23:AD:DR] to 61.67.210.241:8245 (protocol 6)
....
[INFO] Tue Dec 04 13:28:14 2012 Dropped packet from 192.168.0.X to 205.171.76.135 (IP protocol 6) as unable to create new session
[INFO] Tue Dec 04 13:28:14 2012 Internet access port filter dropped packet from 192.168.0.X:2078 [DN:S3:23:AD:DR] to 205.171.76.135:8245 (protocol 6)

While running for few hours the messages did show up only when I rebooted the DNS-323. It looks like is trying to connect only at startup.
Logged

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Re: Internet access
« Reply #5 on: December 05, 2012, 10:19:51 AM »

Hi,
after I waited for a while to get a hold on tech. supp, I gave up and I did some investigation on my own. It looks like "getexip" module tries to connect to all these sites. I have very basic Linux knowledge so I can't tell you a lot. PS yields these results after reboot:
Code: [Select]
1453 root       664 S    getexip
 1454 root       784 S    sh -c wget http://checkip.dyndns.com:8245/ -T 3 -q -O /tmp/wgetpage.txt
 1458 root       716 S    wget http://checkip.dyndns.com:8245/ -T 3 -q -O /tmp/wgetpage.txt
and later
Code: [Select]
....
 1486 root      8856 S    /web/webs
 1507 root       700 S    check_daemon
 1524 root       796 S    crond
 1527 root       496 S    atd
 1576 root      5096 S    smbd -D
 1633 root       664 S    getexip
 1636 root       784 S    sh -c wget http://www.swlink.net/~styma/REMOTE_ADDR.shtml -T 3 -q -O /tmp/wgetpage.txt
 1637 root       720 S    wget http://www.swlink.net/~styma/REMOTE_ADDR.shtml -T 3 -q -O /tmp/wgetpage.txt
....
well, as I said Linux knowledge = 0, but I looked into getexip with a text editor and these commands are hardcoded in there @ offset E9C.
The first url returns the public IP address, but the second one is just dead.
Looking at the second url I wonder if the box was hacked or is just bad DLink code.
I wonder if someone else can confirm that their box behaves the same, that way I can have a bit of piece of mind.

Cheers

Logged

dosborne

  • Level 5 Member
  • *****
  • Posts: 598
Re: Internet access
« Reply #6 on: December 06, 2012, 04:59:51 PM »

Sounds like GetExIp is simply a utility that looks up the external IP address by connecting to a "known" server and gets the IP address returned.
Logged
3 x DNS-323 with 2 x 2TB WD Drives each for a total of 12 TB Storage and Backup. Running DLink Firmware v1.08 and Fonz Fun Plug (FFP) v0.5 for improved software support.

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Re: Internet access
« Reply #7 on: December 06, 2012, 05:39:47 PM »

More so.
1) Why would DNS like to know the external IP address? Unless it uses dyndns which in my case is disabled or wants to open ports behind my back on a upnp router.
2) Why it will be hardcoded with a "well unknown" website (http://www.swlink.net/~styma/REMOTE_ADDR.shtml) which looks more a old days personal page url o***uy named S. Tyma ???
3) Is GetExIp utility the creation of DLink or is a public contribution (sort of open source)?

Anyhow, to be on the safe side I will keep the router blocking all outgoing requests from dns. It works well for me so far and if I don't reboot it I don't even notice its attempts to connect.

Thanks.
Logged

ivan

  • Level 8 Member
  • ***
  • Posts: 1480
Re: Internet access
« Reply #8 on: December 07, 2012, 02:44:09 AM »

Does your unit have Fun_Plug installed?  If so can you just delete the offending utility which might solve your problems.
Logged

d323bkpuser

  • Level 1 Member
  • *
  • Posts: 6
Re: Internet access
« Reply #9 on: December 16, 2012, 10:35:30 AM »

Hi Ivan,
I do have telnet access on the unit. As I previously said I'm not very knowledgeable of linux, but I did a find / -name getexip and found the "utility" in 2 places:
a) /sys/crfs/sbin/getexip
b) /usr/sbin/getexip
I did a rm but the first one can not be deleted - "rm: cannot remove '/sys/crfs/sbin/getexip': Read-only file system". Not quite sure what it means but after rebooting the unit the "utility" is back on both locations and no change in behavior.
Logged