From owner-freebsd-security Wed Jun 6 9:31:53 2001 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-165-226-243.dsl.lsan03.pacbell.net [64.165.226.243]) by hub.freebsd.org (Postfix) with ESMTP id 602E937B401 for ; Wed, 6 Jun 2001 09:31:45 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 1DB15671A4; Wed, 6 Jun 2001 09:31:45 -0700 (PDT) Date: Wed, 6 Jun 2001 09:31:45 -0700 From: Kris Kennaway To: Vladimir Savichev Cc: mikes@ct980320-b.blmngtn1.in.home.com, freebsd-security@freebsd.org Subject: Re: rpc.statd attack before ipfw activated Message-ID: <20010606093144.D15460@xor.obsecurity.org> References: <20010605174214.J90423-100000@ariel.phys.wesleyan.edu> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="HWvPVVuAAfuRc6SZ" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <20010605174214.J90423-100000@ariel.phys.wesleyan.edu>; from vlad@ariel.phys.wesleyan.edu on Tue, Jun 05, 2001 at 05:55:03PM -0400 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --HWvPVVuAAfuRc6SZ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Tue, Jun 05, 2001 at 05:55:03PM -0400, Vladimir Savichev wrote: > how interesting. I'm here on > FreeBSD ariel.phys.wesleyan.edu 4.3-STABLE FreeBSD 4.3-STABLE #2: Sun Jun > 3 21:23:38 EDT 20 01 > root@ariel.phys.wesleyan.edu:/usr/obj/usr/src/sys/ARIEL i386 > I got pretty much similar log several times > for a last couple of days, was wondering > what the hell rpc is doing. Could you point me where I can > read more about. How can I log call hosts. See the archives; this comes up several times a week. Kris --HWvPVVuAAfuRc6SZ Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7HlrwWry0BWjoQKURAtVUAKDvjY6ycTcGgpjmjpxy3owkxvd3FACdHzdQ Ee8Ecwv6Osx52oqGH8V2jPs= =QqBo -----END PGP SIGNATURE----- --HWvPVVuAAfuRc6SZ-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message