Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Ramin Dousti <ramin@cannon.eng.us.uu.net>
To: Daniel Chemko <dchemko@smgtec.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Snuffing out hackers
Date: Wed, 16 Jul 2003 15:47:31 -0400	[thread overview]
Message-ID: <20030716194731.GC27608@cannon.eng.us.uu.net> (raw)
In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com>

This is an icmp(3:3) which means port unreachable. This is an innocent
icmp. However, the question is as to why you receive it on your router
if 24.57.108.11 has nothing to do with you... If it's a correct statement
that it's coming from outside and you don't have anything to do with
24.57.108.11, then the only way it could come to you is by source-routing
which should have been turned off by your ISP in the first place...

Ramin



On Wed, Jul 16, 2003 at 11:58:28AM -0700, Daniel Chemko wrote:

> I am getting some disturbing packet traffic hitting my firewall. Here
> goes:
> 
>  
> 
> IN=eth4 OUT=eth5 SRC=24.87.243.251 DST=24.57.108.11 LEN=76 TOS=0x00
> PREC=0xC0 TTL=25
> 
> 4 ID=17431 PROTO=ICMP TYPE=3 CODE=3 [SRC=24.57.108.11 DST=24.87.243.251
> LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=15860 DF PROTO=TCP SPT=
> 
> 3161 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0 ]
> 
>  
> 
> None of the addresses listed in the packets are from my networks, but
> what is more disturbing is that eth4 is my internal network interface.
> Can anyone see (baring an internal intrusion has occurred) how this can
> happen?
> 
>  
> 
> It definitely appears to be an exploit on my configuration or something.
> 
>  
> 
>  
> 


  parent reply	other threads:[~2003-07-16 19:47 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-07-16 18:58 Snuffing out hackers Daniel Chemko
2003-07-16 19:32 ` Aldo S. Lagana
2003-07-16 19:47 ` Ramin Dousti [this message]
2003-08-01  6:50 ` Pascal Italiaander
  -- strict thread matches above, loose matches on Subject: below --
2003-07-16 20:21 Daniel Chemko
2003-07-16 21:14 ` Sebastian

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030716194731.GC27608@cannon.eng.us.uu.net \
    --to=ramin@cannon.eng.us.uu.net \
    --cc=dchemko@smgtec.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox