Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

Re: Netsh FWPM_NET_EVENT_TYPE_CLASSIFY_DROP

Pavel_APavel_A Member Posts: 2,681
On 28-Oct-2015 03:22, xxxxx@yahoo.com wrote:
> Looks like somebody dropped my pkt, probably NDIS, tcp/ip.sys?
> I even disabled all protocols (except Netmon, ipv4), still I see this pkt drop.
>
> The destination port (i.e. the listening port on machine_1 is a well known port if that means anything here. But I used a ephemeral port as well, see same behavior.).

And what about MAC address? Do you send to the correct peer's MAC
address or to broadcast or multicast?

-- pa

Comments

  • msrmsr Member Posts: 337
    Hi

    I am sending to correct unicast MAC address. Below is the frame dumped from my mux driver. The udp payload is just the SOCKADDR to which this frame is directed

    0: kd> db 0xffffe000`19964282
    ffffe000`19964282 68 05 ca 37 24 48 68 05-ca 37 24 08 08 00 45 00 h..7$Hh..7$...E.
    ffffe000`19964292 00 2c 64 75 00 00 80 11-52 dd c0 a8 01 14 c0 a8 .,du....R.......
    ffffe000`199642a2 01 0a fa 3f 12 b7 00 18-98 ee 00 00 00 00 00 00 ...?............
    ffffe000`199642b2 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
    ffffe000`199642c2 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
    ffffe000`199642d2 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
    ffffe000`199642e2 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
    ffffe000`199642f2 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
  • msrmsr Member Posts: 337
    Turned out, the damn Firewall got enabled on the target.
Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
Developing Minifilters 29 July 2019 OSR Seminar Space
Writing WDF Drivers 23 Sept 2019 OSR Seminar Space
Kernel Debugging 21 Oct 2019 OSR Seminar Space
Internals & Software Drivers 18 Nov 2019 Dulles, VA