From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Daniel Chemko" Subject: Snuffing out hackers Date: Wed, 16 Jul 2003 11:58:28 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C34BCC.3E1AF0FC" Return-path: Content-Class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C34BCC.3E1AF0FC Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable I am getting some disturbing packet traffic hitting my firewall. Here goes: =20 IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 DST=3D24.57.108.11 LEN=3D76 = TOS=3D0x00 PREC=3D0xC0 TTL=3D25 4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 [SRC=3D24.57.108.11 = DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D 3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 ] =20 None of the addresses listed in the packets are from my networks, but what is more disturbing is that eth4 is my internal network interface. Can anyone see (baring an internal intrusion has occurred) how this can happen? =20 It definitely appears to be an exploit on my configuration or something. =20 =20 ------_=_NextPart_001_01C34BCC.3E1AF0FC Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

I am getting some disturbing packet traffic hitting = my firewall. Here goes:

 

IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 = DST=3D24.57.108.11 LEN=3D76 TOS=3D0x00 PREC=3D0xC0 TTL=3D25

4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 = [SRC=3D24.57.108.11 DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 = DF PROTO=3DTCP SPT=3D

3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 = ]

 

None of the addresses listed in the packets are from = my networks, but what is more disturbing is that eth4 is my internal = network interface. Can anyone see (baring an internal intrusion has occurred) = how this can happen?

 

It definitely appears to be an exploit on my = configuration or something.

 

 

=00 ------_=_NextPart_001_01C34BCC.3E1AF0FC-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Aldo S. Lagana" Subject: RE: Snuffing out hackers Date: Wed, 16 Jul 2003 15:32:17 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200307161934.h6GJYajk032145@discmail.com> References: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0003_01C34BAF.703705C0" Return-path: In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: 'Daniel Chemko' , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0003_01C34BAF.703705C0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable Both IP addresses are assigned to cable ISPs. =20 Name: h24-87-243-251.vc.shawcable.net Address: 24.87.243.251 =20 Name: d57-108-11.home.cgocable.net Address: 24.57.108.11 =20 Not sure if either of them are your ISP? But I would contact both ISPs = with your log data if you really cared. Are you running squid? A webserver? =20 _____ =20 From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko Sent: Wednesday, July 16, 2003 2:58 PM To: netfilter@lists.netfilter.org =20 I am getting some disturbing packet traffic hitting my firewall. Here = goes: =20 IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 DST=3D24.57.108.11 LEN=3D76 = TOS=3D0x00 PREC=3D0xC0 TTL=3D25 4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 [SRC=3D24.57.108.11 = DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D 3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 ] =20 None of the addresses listed in the packets are from my networks, but = what is more disturbing is that eth4 is my internal network interface. Can = anyone see (baring an internal intrusion has occurred) how this can happen? =20 It definitely appears to be an exploit on my configuration or something. =20 =20 ------=_NextPart_000_0003_01C34BAF.703705C0 Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable

Both IP addresses are assigned to = cable ISPs…

 

Name:    h24-87-243-251.vc.shawcable.net

Address:  = 24.87.243.251

 

Name:    d57-108-11.home.cgocable.net

Address:  = 24.57.108.11

 

Not sure if either of them are your ISP?  But I would contact both ISPs with your log data if you = really cared.  Are you running squid?  A webserver?

 


From: netfilter-admin@lists.netfilter.org = [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel = Chemko
Sent: Wednesday, July 16, = 2003 2:58 PM
To: = netfilter@lists.netfilter.org

 

I am getting some disturbing packet traffic hitting = my firewall. Here goes:

 

IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 = DST=3D24.57.108.11 LEN=3D76 TOS=3D0x00 PREC=3D0xC0 TTL=3D25

4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 = [SRC=3D24.57.108.11 DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D

3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 = ]

 

None of the addresses listed in the packets are from = my networks, but what is more disturbing is that eth4 is my internal = network interface. Can anyone see (baring an internal intrusion has occurred) = how this can happen?

 

It definitely appears to be an exploit on my = configuration or something.

 

 

------=_NextPart_000_0003_01C34BAF.703705C0-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Dousti Subject: Re: Snuffing out hackers Date: Wed, 16 Jul 2003 15:47:31 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030716194731.GC27608@cannon.eng.us.uu.net> References: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Daniel Chemko Cc: netfilter@lists.netfilter.org This is an icmp(3:3) which means port unreachable. This is an innocent icmp. However, the question is as to why you receive it on your router if 24.57.108.11 has nothing to do with you... If it's a correct statement that it's coming from outside and you don't have anything to do with 24.57.108.11, then the only way it could come to you is by source-routing which should have been turned off by your ISP in the first place... Ramin On Wed, Jul 16, 2003 at 11:58:28AM -0700, Daniel Chemko wrote: > I am getting some disturbing packet traffic hitting my firewall. Here > goes: > > > > IN=eth4 OUT=eth5 SRC=24.87.243.251 DST=24.57.108.11 LEN=76 TOS=0x00 > PREC=0xC0 TTL=25 > > 4 ID=17431 PROTO=ICMP TYPE=3 CODE=3 [SRC=24.57.108.11 DST=24.87.243.251 > LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=15860 DF PROTO=TCP SPT= > > 3161 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0 ] > > > > None of the addresses listed in the packets are from my networks, but > what is more disturbing is that eth4 is my internal network interface. > Can anyone see (baring an internal intrusion has occurred) how this can > happen? > > > > It definitely appears to be an exploit on my configuration or something. > > > > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Daniel Chemko" Subject: RE: Snuffing out hackers Date: Wed, 16 Jul 2003 13:21:55 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <7C9884991ADAE0479C14F10C858BCDF5122DF7@alderaan.smgtec.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C34BD7.E6BB5D6E" Return-path: Content-Class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: "Aldo S. Lagana" , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C34BD7.E6BB5D6E Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable I am on Shaw, but none of these addresses are used for anything to do with my network. =20 I am doing some pretty anal filtering, but then again, I may be missing something pretty obvious. I have rp_filter at 2 and source routing disabled. =20 PS: I am getting MANY of these packets. These packets are not getting through to their targets, but if someone is persistent enough to keep trying, I assume they must be able to do something malicious. =20 -----Original Message----- From: Aldo S. Lagana [mailto:alagana@discmail.com]=20 Sent: Wednesday, July 16, 2003 12:32 PM To: Daniel Chemko; netfilter@lists.netfilter.org Subject: RE: Snuffing out hackers =20 Both IP addresses are assigned to cable ISPs... =20 Name: h24-87-243-251.vc.shawcable.net Address: 24.87.243.251 =20 Name: d57-108-11.home.cgocable.net Address: 24.57.108.11 =20 Not sure if either of them are your ISP? But I would contact both ISPs with your log data if you really cared. Are you running squid? A webserver? =20 _____ =20 From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko Sent: Wednesday, July 16, 2003 2:58 PM To: netfilter@lists.netfilter.org =20 I am getting some disturbing packet traffic hitting my firewall. Here goes: =20 IN=3Deth4 OUT=3Deth5 SRC=3D24.87.243.251 DST=3D24.57.108.11 LEN=3D76 = TOS=3D0x00 PREC=3D0xC0 TTL=3D25 4 ID=3D17431 PROTO=3DICMP TYPE=3D3 CODE=3D3 [SRC=3D24.57.108.11 = DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 TTL=3D117 ID=3D15860 DF PROTO=3DTCP = SPT=3D 3161 DPT=3D80 WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 ] =20 None of the addresses listed in the packets are from my networks, but what is more disturbing is that eth4 is my internal network interface. Can anyone see (baring an internal intrusion has occurred) how this can happen? =20 It definitely appears to be an exploit on my configuration or something. =20 =20 ------_=_NextPart_001_01C34BD7.E6BB5D6E Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

I am on Shaw, but none of these = addresses are used for anything to do with my network.

 

I am doing some pretty anal = filtering, but then again, I may be missing something pretty obvious. I have rp_filter = at 2 and source routing disabled.

 

PS: I am getting MANY of these = packets. These packets are not getting through to their targets, but if someone is = persistent enough to keep trying, I assume they must be able to do something = malicious.

 

-----Original = Message-----
From: Aldo S. Lagana [mailto:alagana@discmail.com]
Sent: Wednesday, July 16, = 2003 12:32 PM
To: Daniel Chemko; netfilter@lists.netfilter.org
Subject: RE: Snuffing out = hackers

 

Both IP = addresses are assigned to cable ISPs…

 

Name:  =   h24-87-243-251.vc.shawcable.net

Address:  24.87.243.251

 

Name:  =   d57-108-11.home.cgocable.net

Address:  24.57.108.11

 

Not sure if = either of them are your ISP?  But I would contact both ISPs with your log = data if you really cared.  Are you running squid?  A = webserver?

 


From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko
Sent: Wednesday, July 16, = 2003 2:58 PM
To: = netfilter@lists.netfilter.org

 

I am getting some = disturbing packet traffic hitting my firewall. Here goes:

 

IN=3Deth4 OUT=3Deth5 = SRC=3D24.87.243.251 DST=3D24.57.108.11 LEN=3D76 TOS=3D0x00 PREC=3D0xC0 = TTL=3D25

4 ID=3D17431 PROTO=3DICMP = TYPE=3D3 CODE=3D3 [SRC=3D24.57.108.11 DST=3D24.87.243.251 LEN=3D48 TOS=3D0x00 PREC=3D0x00 = TTL=3D117 ID=3D15860 DF PROTO=3DTCP SPT=3D

3161 DPT=3D80 = WINDOW=3D16384 RES=3D0x00 SYN URGP=3D0 ]

 

None of the addresses = listed in the packets are from my networks, but what is more disturbing is that eth4 = is my internal network interface. Can anyone see (baring an internal intrusion = has occurred) how this can happen?

 

It definitely appears to be = an exploit on my configuration or something.

 

 

=00 ------_=_NextPart_001_01C34BD7.E6BB5D6E-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Sebastian" Subject: RE: Snuffing out hackers Date: Wed, 16 Jul 2003 23:14:34 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000f01c34bdf$415d9c70$0200a8c0@basti79> References: <7C9884991ADAE0479C14F10C858BCDF5122DF7@alderaan.smgtec.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF7@alderaan.smgtec.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: 'Daniel Chemko' , Netfilter Mailinglist Hi there... Just a thought: If you are getting many of those packtes, than it should be possible to catch one of it with tcpdump to find out senders MAC address. This will pearhaps allow to find you the source, if it's realy located on your internal network. Greets Sebastian. -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko Sent: Wednesday, July 16, 2003 10:22 PM To: Aldo S. Lagana; netfilter@lists.netfilter.org Subject: RE: Snuffing out hackers I am on Shaw, but none of these addresses are used for anything to do with my network. I am doing some pretty anal filtering, but then again, I may be missing something pretty obvious. I have rp_filter at 2 and source routing disabled. PS: I am getting MANY of these packets. These packets are not getting through to their targets, but if someone is persistent enough to keep trying, I assume they must be able to do something malicious. -----Original Message----- From: Aldo S. Lagana [mailto:alagana@discmail.com] Sent: Wednesday, July 16, 2003 12:32 PM To: Daniel Chemko; netfilter@lists.netfilter.org Subject: RE: Snuffing out hackers Both IP addresses are assigned to cable ISPs. Name: h24-87-243-251.vc.shawcable.net Address: 24.87.243.251 Name: d57-108-11.home.cgocable.net Address: 24.57.108.11 Not sure if either of them are your ISP? But I would contact both ISPs with your log data if you really cared. Are you running squid? A webserver? From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Daniel Chemko Sent: Wednesday, July 16, 2003 2:58 PM To: netfilter@lists.netfilter.org I am getting some disturbing packet traffic hitting my firewall. Here goes: IN=eth4 OUT=eth5 SRC=24.87.243.251 DST=24.57.108.11 LEN=76 TOS=0x00 PREC=0xC0 TTL=25 4 ID=17431 PROTO=ICMP TYPE=3 CODE=3 [SRC=24.57.108.11 DST=24.87.243.251 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=15860 DF PROTO=TCP SPT= 3161 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0 ] None of the addresses listed in the packets are from my networks, but what is more disturbing is that eth4 is my internal network interface. Can anyone see (baring an internal intrusion has occurred) how this can happen? It definitely appears to be an exploit on my configuration or something. From mboxrd@z Thu Jan 1 00:00:00 1970 From: Pascal Italiaander Subject: Re: Snuffing out hackers Date: Fri, 1 Aug 2003 08:50:55 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200308010850.55270.pc-secure@home.nl> References: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF5122DF6@alderaan.smgtec.com> Content-Disposition: inline Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Op woensdag 16 juli 2003 20:58, schreef Daniel Chemko: > I am getting some disturbing packet traffic hitting my firewall. Here > goes: > > > > IN=eth4 OUT=eth5 SRC=24.87.243.251 DST=24.57.108.11 LEN=76 TOS=0x00 > PREC=0xC0 TTL=25 > > 4 ID=17431 PROTO=ICMP TYPE=3 CODE=3 [SRC=24.57.108.11 DST=24.87.243.251 > LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=15860 DF PROTO=TCP SPT= > > 3161 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0 ] > > > > None of the addresses listed in the packets are from my networks, but > what is more disturbing is that eth4 is my internal network interface. > Can anyone see (baring an internal intrusion has occurred) how this can > happen? > > > > It definitely appears to be an exploit on my configuration or something. To snif out hackers , to watch their activities, or block them ,you could put a bridge in front of your firewall ( OpenBSD perhaps ). Since the bridge has no IP-address no hacker noticed that you're watching, or has no clue what blocks him. Even better , the bridge can not be attacked or hacked. ( since there is no ip-address the bridge is NOT seen as a part of youre network , no extra HOP is seen, makes it almost invissible ) Some advanced method could be a honeypot. This can give you more output about attacks or whatever an intruder wants to. Pascal