From: "Aldo S. Lagana" <alagana@discmail.com>
To: 'Daniel Chemko' <dchemko@smgtec.com>, netfilter@lists.netfilter.org
Subject: RE: Snuffing out hackers
Date: Wed, 16 Jul 2003 15:32:17 -0400 [thread overview]
Message-ID: <200307161934.h6GJYajk032145@discmail.com> (raw)
In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com>
[-- Attachment #1: Type: text/plain, Size: 1254 bytes --]
Both IP addresses are assigned to cable ISPs.
Name: h24-87-243-251.vc.shawcable.net
Address: 24.87.243.251
Name: d57-108-11.home.cgocable.net
Address: 24.57.108.11
Not sure if either of them are your ISP? But I would contact both ISPs with
your log data if you really cared. Are you running squid? A webserver?
_____
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko
Sent: Wednesday, July 16, 2003 2:58 PM
To: netfilter@lists.netfilter.org
I am getting some disturbing packet traffic hitting my firewall. Here goes:
IN=eth4 OUT=eth5 SRC=24.87.243.251 DST=24.57.108.11 LEN=76 TOS=0x00
PREC=0xC0 TTL=25
4 ID=17431 PROTO=ICMP TYPE=3 CODE=3 [SRC=24.57.108.11 DST=24.87.243.251
LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=15860 DF PROTO=TCP SPT=
3161 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0 ]
None of the addresses listed in the packets are from my networks, but what
is more disturbing is that eth4 is my internal network interface. Can anyone
see (baring an internal intrusion has occurred) how this can happen?
It definitely appears to be an exploit on my configuration or something.
[-- Attachment #2: Type: text/html, Size: 5727 bytes --]
next prev parent reply other threads:[~2003-07-16 19:32 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-07-16 18:58 Snuffing out hackers Daniel Chemko
2003-07-16 19:32 ` Aldo S. Lagana [this message]
2003-07-16 19:47 ` Ramin Dousti
2003-08-01 6:50 ` Pascal Italiaander
-- strict thread matches above, loose matches on Subject: below --
2003-07-16 20:21 Daniel Chemko
2003-07-16 21:14 ` Sebastian
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200307161934.h6GJYajk032145@discmail.com \
--to=alagana@discmail.com \
--cc=dchemko@smgtec.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox