Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 3 Nov 1998 22:18:55 -0800 (PST)
From:      Archie Cobbs <archie@whistle.com>
To:        alla@sovlink.ru (Alla Bezroutchko)
Cc:        security@FreeBSD.ORG
Subject:   Re: Is it an attack? Strange things logged by ipfw.
Message-ID:  <199811040618.WAA20681@bubba.whistle.com>
In-Reply-To: <363EBD86.74C9F6E2@sovlink.ru> from Alla Bezroutchko at "Nov 3, 98 11:23:34 am"

next in thread | previous in thread | raw e-mail | index | archive | help
Alla Bezroutchko writes:
> I have an ipfw-based firewall and noticed a peculiar connections in its
> logs. Maybe this is some new kind of attack? Any comments appreciated.
> Here are the logs:
> 
> Nov  3 00:44:53 buddy /kernel: ipfw: 65534 Deny TCP a.b.c.d:50818
> aaa.aaa.aaa.aaa:1333 in via ex0
> Nov  3 01:12:51 buddy /kernel: ipfw: 65534 Deny TCP e.f.g.h:50818
> aaa.aaa.aaa.aaa:1565 in via ex0
> Nov  2 11:15:37 buddy /kernel: ipfw: 65534 Deny TCP i.j.k.l:50818
> aaa.aaa.aaa.aaa:1725 in via ex0
> Oct 20 04:20:03 buddy /kernel: ipfw: 65534 Deny TCP m.n.o.p:50818
> aaa.aaa.aaa.aaa:2349 in via ex0
> Oct 20 09:22:35 buddy /kernel: ipfw: 65534 Deny TCP q.r.s.t:50818
> aaa.aaa.aaa.aaa:1493 in via ex0
> Oct 19 04:35:01 buddy /kernel: ipfw: 65534 Deny TCP u.v.w.x:50818
> aaa.aaa.aaa.aaa:2465 in via ex0

One lesson I've learned over the years: never rule out
broken Windows machines :-)

-Archie

___________________________________________________________________________
Archie Cobbs   *   Whistle Communications, Inc.  *   http://www.whistle.com

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199811040618.WAA20681>