From owner-freebsd-security Thu Mar 8 6:39:22 2001 Delivered-To: freebsd-security@freebsd.org Received: from ohm.physics.purdue.edu (ohm.physics.purdue.edu [128.210.146.32]) by hub.freebsd.org (Postfix) with ESMTP id 64FFF37B718 for ; Thu, 8 Mar 2001 06:39:15 -0800 (PST) (envelope-from will@physics.purdue.edu) Received: (from will@localhost) by ohm.physics.purdue.edu (8.11.2/8.9.3) id f28EeuF48093; Thu, 8 Mar 2001 09:40:56 -0500 (EST) (envelope-from will@physics.purdue.edu) X-Authentication-Warning: ohm.physics.purdue.edu: will set sender to will@physics.purdue.edu using -f Date: Thu, 8 Mar 2001 09:40:55 -0500 From: Will Andrews To: Will Mitayai Keeso Rowe Cc: tjk@tksoft.com, Will Mitayai Keeso Rowe , will@physics.purdue.edu, freebsd-security@FreeBSD.ORG Subject: Re: strange messages Message-ID: <20010308094055.L45561@ohm.physics.purdue.edu> Reply-To: Will Andrews References: <200103081428.GAA02075@uno.tksoft.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="m+jEI8cDoTn6Mu9E" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from mit@mitayai.net on Thu, Mar 08, 2001 at 09:33:30AM -0500 X-Operating-System: FreeBSD 4.2-STABLE i386 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --m+jEI8cDoTn6Mu9E Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Mar 08, 2001 at 09:33:30AM -0500, Will Mitayai Keeso Rowe wrote: > Acording to CERT (the latest statd message seems to be > http://www.kb.cert.org/vuls/id/34043) > FreeBSD is not vulnerable to rpc.statd problems. >=20 > But, i still have a question... how can i better log attempts to hack my > machine's rpc.statd? It would be nice to have an IP of the connecting box= so > i can see if they are doing it remotely or by an account on my machine. Tcpwrappers or ipfw? What good is this information? --=20 wca --m+jEI8cDoTn6Mu9E Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.3 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE6p5n3F47idPgWcsURAkd+AJ9KnJHY9Tl6l2Z8g/asqH7xXJHloACeLDQ6 KU2gigN+L+L62nGzDL1S5xQ= =SSBo -----END PGP SIGNATURE----- --m+jEI8cDoTn6Mu9E-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message