Quote Originally Posted by Albretch
I am not using a hub I am connecting to the internet directly from my NIC in a "NIC <-.-> dsl modem <-.-> outgoing cable" configuration

Is there anything else or new you would recommend to me?
knopnet is correct; if you get your copy of the ISO from a mirror you should definately check the md5 against the proper md5. And if you believe that your source may have modified the iso then it makes no sense to check it against the md5 from that source, check it against other mirrors.

But as to your traffic with China, I'm amazed that you are concerned about security and Internet traffic but don't run with the hardware firewall protection that an inexpensive router gives you. I thought you were seeing these packets as Knoppix boots, but since you must already be booted to run ethereal then I now understand that you are seeing them after booting, and without a hardware firewall what you are actually seeing is simply traffic from China looking for users without hardware firewalls to infect the systems of. See also answer #4. There is an amazing amount of this type traffic on any Iternet connection, and one would be a fool to not block it.

Software firewalls are not sufficent. Particularly with Windows, which has awful security and is the system most of these attacks are looking for. Microsoft is said to have put some back doors in their firewall which the hackers know how to exploit. But even without that, before a softwall firewall can examine packets and decide if they should pass or not, those packets mush have beem processed by a good part of the TCI/IP stack. Micfrosoft is so troubled by buffer overflows and other poor programming bugs that you can't count on a software firewall to protexct you if the hacker can exploit buffer overflows before the software firewall ever sees the packet.

What I had intended to do was set up ethereal on a second systen and by using a hub so that I could see all of the traffic out of and into my Knoppix system, watch the traffic during a Knoppix boot. Since I'm behind a hardware firewall I know any such traffic that I see would originate on the Knoppix end. I should see packets to the same address as you. But if you are running without a NAT router then I'm not going to further waste my time chasing ghosts, I'm confident that your China packets are responses to packets from the plague of attacks always on the Internet. (It is said that a fress new Install of Windows will be infected in 4 minutes or less, before it can even install the "security updates" it needs, if it is exposed directly to the internet and not behind a router.)

Since you have concerns, I would suggest that you get a NAT router and try this again. A nice side effect is that you will not need to run PPPoE software in Knoppix. But most important will be that you will have a hardware firewall. After you get that I suggest looking very closely at your Windows install and removing all the viruses that are there. And be sure to check fior rootkits, software that is designed to hid itself and it's activity by intercepting the normal disk access calls made to windows and lie about the hard disk when those calls would give it away. There are some software approaches that can find rootkits (such as a raw read of the individual sectors of the disk and the scanning software putting back together the file system and comparing that against what the results of normal system calls return). The rootkits, of course, are getting smarter too so it's an ongoing battle to continue to be able to detect them. One good way that can't be stopped by rootkit software is to watch the Internet traffic for telltale packets from a second trusted computer. For this you do need a hub (or resort to ARP poisonning in a switch, which I do not advise).