Firewall Wizards mailing list archives

VDOLive weirdness


From: Drexx Laggui <drexx () pacific net sg>
Date: Thu, 27 Apr 2000 18:38:19 +0800

April 27, 2000 (GMT +8)

Hello world,

Can anybody point me to a detailed reference on how VDOLive
works? Looking at my tcpdump output, connecting to a site
involves connections from three servers, and not just the original
one I was originally browsing. Very firewall unfriendly.

1] My PC connects via TCP/7000 to 203.116.81.41
http://onezine.s-one.net.sg/s-onezine/980619M/SCV_roadshow/calendarone.vdo
from this URL webpage:
http://onezine.s-one.net.sg/s-onezine/980619M/SCV_roadshow/index.htm

2] The weird thing is that 203.116.81.59 is sending stuff to my PC
via an arranged UDP high-port, which my PC was waiting to accept
(as seen by "netstat -na"). FW-1 naturally denies this unknown
connection, but I still hate knowing their is a race condition between
the VDOLive server and some lucky crackers.

3] The 2nd weird thing is that my PC again connects via TCP/7010
to 207.88.23.100 (vdo-ds3.vdo.net). What in the world is VDONet's
role in here? I tried it both from outside/inside my FireWall-1, and
there is no obvious participation (e.g. no ads, nor anything) from
VDONet. 

thanks in advance,

Drexx Laggui <drexx () pacific net sg>



Current thread: