查看: 4631|回复: 8
收起左侧

[求助] SEP提示检测到[SID:21590]P2P EDONKEY PING MESSAGE

[复制链接]
godspeed_mason
发表于 2010-4-26 13:06:40 | 显示全部楼层 |阅读模式
如题
这是什么意思
貌似一开迅雷就有这提示?
Inner
发表于 2010-4-26 13:14:37 | 显示全部楼层
本帖最后由 Inner 于 2010-4-26 13:16 编辑

Severity: Medium
This attack could pose a moderate security threat. It does not require immediate action.
Description
This signature detects the Ping messages between an eDonkey client and an eDonkey server.
Additional Information
The use of certain P2P applications is restricted in certain environments. EDonkey is a file sharing application that is available at edonkey2000.com. The eDonkey client supports the Overnet network as well as the eDonkey network.

The eDonkey network (also called eDonkey2000 network or ed2k) is a file sharing network used primarily to exchange music, movies, and software. Like most file sharing networks, it is decentralized; files are not stored on a central server but are exchanged directly between users based on the peer-to-peer principle.

The eDonkey client programs connect to the network to share files. eDonkey servers act as communication hubs for the clients and allow users to locate files within the network. Clients and servers are available for Windows, Macintosh, Linux, and other UNIX variants. Anyone can add a server to the network. Because of constant changes to the server network, clients update their server lists regularly.

The eDonkey network uses a compound MD4 hash checksum to identify files, which allows identification of identical files with different file names, as well as distinction of differing files with identical file names. Another feature of eDonkey is that for files greater than approximately 9.8 MB, it shares file segments before the download completes. This speeds up the distribution of large files throughout the network.

Affected
Windows, Mac, and Linux

Response
Uninstall the eDonkey application if its use is restricted by the network policy.

Possible False Positives
There are no known cases of false positives associated with this signature.


楼主自定义了什么规则没有,我虚拟机里貌似没有楼主的现象(SEP 11R6+最新版迅雷/电驴)
千夏奈奈
发表于 2010-4-26 13:14:48 | 显示全部楼层
收到电驴 PING MESSAGE

具体不知道,没碰到过
zhilu
发表于 2010-4-26 13:21:02 | 显示全部楼层
迅雷向外部发送信息被防火墙检查到了而已,至于发送什么信息,这个就。。。
godspeed_mason
 楼主| 发表于 2010-4-26 13:55:28 | 显示全部楼层
啥都没定义
就是装了SEP
迅雷自动往外发信息?
这么猥琐?
chuibuzou
发表于 2010-4-26 14:24:47 | 显示全部楼层
可能是在请求资源吧,迅雷也会传东西上去,P2P就是这样,你下载的东西同时也在分享给别人,用360的流量监控发现刚用迅雷下完东西任务结束了,它还是在往上传,所以现在换成orbit了,不会偷偷上传,资源占用非常小
on-the-fly
发表于 2010-4-26 14:36:48 | 显示全部楼层
迅雷的问题,下个雨林木风版的,把偷偷上传屏蔽掉,这样能好一点,不过还是会有上传
wodewowo
头像被屏蔽
发表于 2010-4-26 20:08:19 | 显示全部楼层
啥都没定义
就是装了SEP
迅雷自动往外发信息?
这么猥琐?
godspeed_mason 发表于 2010-4-26 13:55



    迅雷偏偏就是这么猥琐
luobinhan23
头像被屏蔽
发表于 2010-4-26 23:56:02 | 显示全部楼层
再次證明了迅雷的猥琐
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-10-6 09:41 , Processed in 0.138558 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表