From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Aldo S. Lagana" Subject: RE: Snuffing out hackers Date: Wed, 16 Jul 2003 15:32:17 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200307161934.h6GJYajk032145@discmail.com> References: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0003_01C34BAF.703705C0" Return-path: In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: 'Daniel Chemko' , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0003_01C34BAF.703705C0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable Both IP addresses are assigned to cable ISPs. =20 Name: h24-87-243-251.vc.shawcable.net Address: 24.87.243.251 =20 Name: d57-108-11.home.cgocable.net Address: 24.57.108.11 =20 Not sure if either of them are your ISP? But I would contact both ISPs = with your log data if you really cared. Are you running squid? A webserver? =20 _____ =20 From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko Sent: Wednesday, July 16, 2003 2:58 PM To: netfilter@lists.netfilter.org =20 I am getting some disturbing packet traffic hitting my firewall. Here = goes: =20 IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 DST=3D24.57.108.11 LEN=3D76 = TOS=3D0x00 PREC=3D0xC0 TTL=3D25 4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 [SRC=3D24.57.108.11 = DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D 3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 ] =20 None of the addresses listed in the packets are from my networks, but = what is more disturbing is that eth4 is my internal network interface. Can = anyone see (baring an internal intrusion has occurred) how this can happen? =20 It definitely appears to be an exploit on my configuration or something. =20 =20 ------=_NextPart_000_0003_01C34BAF.703705C0 Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable

Both IP addresses are assigned to = cable ISPs…

 

Name:    h24-87-243-251.vc.shawcable.net

Address:  = 24.87.243.251

 

Name:    d57-108-11.home.cgocable.net

Address:  = 24.57.108.11

 

Not sure if either of them are your ISP?  But I would contact both ISPs with your log data if you = really cared.  Are you running squid?  A webserver?

 


From: netfilter-admin@lists.netfilter.org = [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel = Chemko
Sent: Wednesday, July 16, = 2003 2:58 PM
To: = netfilter@lists.netfilter.org

 

I am getting some disturbing packet traffic hitting = my firewall. Here goes:

 

IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 = DST=3D24.57.108.11 LEN=3D76 TOS=3D0x00 PREC=3D0xC0 TTL=3D25

4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 = [SRC=3D24.57.108.11 DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D

3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 = ]

 

None of the addresses listed in the packets are from = my networks, but what is more disturbing is that eth4 is my internal = network interface. Can anyone see (baring an internal intrusion has occurred) = how this can happen?

 

It definitely appears to be an exploit on my = configuration or something.

 

 

------=_NextPart_000_0003_01C34BAF.703705C0--