Date: Mon, 7 Jan 2002 14:36:11 -0200 (BRST) From: Paulo Fragoso <paulo@nlink.com.br> To: <freebsd-security@freebsd.org> Subject: LAST_ACK traffic? Message-ID: <20020107141924.C55391-100000@mirage.nlink.com.br>
next in thread | raw e-mail | index | archive | help
Hi, In our network there are some workstation under a firewall, today we ware looking our internal traffic, there was one workstation sending packets to one webserver at 200kbps: roto Recv-Q Send-Q Local Address Foreign Address (state) tcp4 0 0 our.work.station.1412 200.226.137.10.80 LAST_ACK The user that workstation was using Opera 6.0 for linux (on FreeBSD 4.4-RELEASE). The strange traffic had started after the he closed the opera. Are there any secure problem with this? Why our workstation was send packets of LAST_ACK whithout any processes bound at 1412 (checked with lsof)? Many Thanks, Paulo Fragoso. -- __O _-\<,_ Why drive when you can bike? (_)/ (_) To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020107141924.C55391-100000>