Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Why is a generic host process trying to hit cais.net?

Reply
Thread Tools Display Modes

Why is a generic host process trying to hit cais.net?

 
 
Tony Toews [MVP]
Guest
Posts: n/a

 
      12-09-2007
Folks

My outgoing firewall on Windows XP SP2 fully patched is telling me
that the Generic Host process for Win32 Services is trying to hit
63-217-20-36.sdsl.cais.net - IP address is 63.217.20.36.

There are quite a number of other IP address ranges none of which
belong to Microsoft. The port 443 hits to indeed belong to Microsoft
so I've permitted my firewall to pass those.

What the heck is going on? In the past the IP addresses belonged to
akamai.net so I was willing go along with that.

I *DESPISE* how Microsoft has made these generic host processes so
utterly difficult to understand and track just what the heck is going
on.

Tony

--
Tony Toews, Microsoft Access MVP
Please respond only in the newsgroups so that others can
read the entire thread of messages.
Microsoft Access Links, Hints, Tips & Accounting Systems at
http://www.granite.ab.ca/accsmstr.htm
Tony's Microsoft Access Blog - http://msmvps.com/blogs/access/
 
Reply With Quote
 
 
 
 
Tony Toews [MVP]
Guest
Posts: n/a

 
      12-09-2007
"Tony Toews [MVP]" <> wrote:

>My outgoing firewall on Windows XP SP2 fully patched is telling me
>that the Generic Host process for Win32 Services is trying to hit
>63-217-20-36.sdsl.cais.net - IP address is 63.217.20.36.


BTW just to make this clear. This happens when Microsoft Update is
executing as well. So the Generic Host Process is being initiated by
Microsoft Update as well as on it's own.

Tony
--
Tony Toews, Microsoft Access MVP
Please respond only in the newsgroups so that others can
read the entire thread of messages.
Microsoft Access Links, Hints, Tips & Accounting Systems at
http://www.granite.ab.ca/accsmstr.htm
Tony's Microsoft Access Blog - http://msmvps.com/blogs/access/
 
Reply With Quote
 
Robert Aldwinckle
Guest
Posts: n/a

 
      12-09-2007
"Tony Toews [MVP]" <> wrote in message
news:...
> Folks
>
> My outgoing firewall on Windows XP SP2 fully patched is telling me
> that the Generic Host process for Win32 Services is trying to hit
> 63-217-20-36.sdsl.cais.net - IP address is 63.217.20.36.
>
> There are quite a number of other IP address ranges none of which
> belong to Microsoft. The port 443 hits to indeed belong to Microsoft
> so I've permitted my firewall to pass those.
>
> What the heck is going on? In the past the IP addresses belonged to
> akamai.net so I was willing go along with that.



Perhaps its just a symptom of an out-of-date reverse lookup?
Take a netcap trace and format it with Ethereal (aka WireShark).
Look for a DNS exchange which involves that IP address.
E.g. if that address was returned in a lookup request, what name
was used? Or if that name was used why was it used?
(Perhaps by a redirect for a more acceptable request?)

BTW here's a clue from telnet (just requesting that IP address):

<telnet>
Server: AkamaiGHost
</telnet>

MS contracts with Akamai; perhaps Akamai subcontracts to other hosts?


>
> I *DESPISE* how Microsoft has made these generic host processes so
> utterly difficult to understand and track just what the heck is going
> on.



Me too! <eg>


Good luck

Robert Aldwinckle
---


 
Reply With Quote
 
MowGreen [MVP]
Guest
Posts: n/a

 
      12-10-2007
Robert Aldwinckle wrote:

> "Tony Toews [MVP]" <> wrote in message
> news:...
>
>>Folks
>>
>>My outgoing firewall on Windows XP SP2 fully patched is telling me
>>that the Generic Host process for Win32 Services is trying to hit
>>63-217-20-36.sdsl.cais.net - IP address is 63.217.20.36.
>>
>>There are quite a number of other IP address ranges none of which
>>belong to Microsoft. The port 443 hits to indeed belong to Microsoft
>>so I've permitted my firewall to pass those.
>>
>>What the heck is going on? In the past the IP addresses belonged to
>>akamai.net so I was willing go along with that.

>
>
> Perhaps its just a symptom of an out-of-date reverse lookup?
> Take a netcap trace and format it with Ethereal (aka WireShark).
> Look for a DNS exchange which involves that IP address.
> E.g. if that address was returned in a lookup request, what name
> was used? Or if that name was used why was it used?
> (Perhaps by a redirect for a more acceptable request?)
>
> BTW here's a clue from telnet (just requesting that IP address):
>
> <telnet>
> Server: AkamaiGHost
> </telnet>
>
> MS contracts with Akamai; perhaps Akamai subcontracts to other hosts?
>
>>I *DESPISE* how Microsoft has made these generic host processes so
>>utterly difficult to understand and track just what the heck is going
>>on.

>
> Me too! <eg>
>
> Good luck
>
> Robert Aldwinckle
> ---



Is this Version 2.0 of 'Trustworthy Computing'? <()>


MowGreen [MVP 2003-2008]
===============
*-343-* FDNY
Never Forgotten
===============
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RE: Generic host process for win 32 services ? dingaz Windows Update 2 11-07-2008 03:05 PM
Re: HELP ME PLEASE !!!!Generic Host Process for Win32 Services has enc lumo Windows Update 0 02-27-2007 01:52 PM
Re: Generic host process for win 32 services ? David H. Lipman Windows Update 3 01-07-2007 05:17 AM
RE: Generic host process for win 32 services ? So sound here Windows Update 0 09-05-2004 01:33 PM
Re: Generic host process for win 32 services ? Derek Cheng [MSFT] Windows Update 0 08-25-2004 01:36 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59