All of lore.kernel.org
 help / color / mirror / Atom feed
* Samba "Leak"
@ 2004-07-07 19:23 David Cary Hart
  2004-07-07 19:35 ` Antony Stone
  0 siblings, 1 reply; 4+ messages in thread
From: David Cary Hart @ 2004-07-07 19:23 UTC (permalink / raw)
  To: netfilter

I cannot figure this out. Our server - running IPTables - has very few
ports open to input and the default is Drop. While a substantial number
of 139 and 445 packets show up in the log as rejected, I am seeing a few
attempts to connect to Samba in the log. These are identified by WAN IPs
so they are not spoofing localhost or a LAN IP.

I also have INVALID and fragmented packets rejected so that path is
closed.

So far, nobody has actually gained access, yet it is disconcerting. Any
ideas how these are getting past the firewall?

-- 
                            David Cary Hart
Hart's PGP key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x58A60BB1



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-07-07 22:03 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-07 19:23 Samba "Leak" David Cary Hart
2004-07-07 19:35 ` Antony Stone
2004-07-07 21:52   ` David Cary Hart
2004-07-07 22:03     ` Antony Stone

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.