Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 4 Sep 1997 09:38:10 +0100 (WET DST)
From:      Klaus Lichtenwalder <Klaus.Lichtenwalder@WebForum.DE>
To:        Prashant Dongre <pdongre@opentech.stpn.soft.net>
Cc:        ArkanoiD <ark@paranoid.convey.ru>, firewalls@GreatCircle.COM, freebsd-security@FreeBSD.ORG
Subject:   Re: log connection attempts?
Message-ID:  <Pine.LNX.3.95.970904093638.27174B-100000@gaston.m.isar.de>
In-Reply-To: <340EE174.C45D396F@opentech.stpn.soft.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 4 Sep 1997, Prashant Dongre wrote:

> ArkanoiD wrote:
> > nuqneH,
> >
> > Did anyone try to patch the kernel to log connection attempts for ports
> > (tcp and maybe udp) where no program accepts connection? (2.1.7)
> >
> > I _know_ i can do nearly the same with IP filtering/logging but i
> > prefer another way..
> >
> [...]
>   Have you configured kernel for IPFW (IP Firewall) ?.
> 
> IPFW does log connection attempts for the ports which are blocked for a network.
> 
> Messages get into /var/log/messages and also displayed on the console.
> 
> Prashant
> 

There's a patch for linux out that logs connection attempts to unserved
ports. Might be worth a look if somebody tries to port sth like this to
different os'.

Klaus

-- 
 Klaus Lichtenwalder, Dipl. Inform.,   PGP Key: email to key@Four11.com
 Lichtenwalder@ACM.org                          http://www.wp.com/Klaus
 K.Lichtenwalder@Computer.org                      fax: +49-89-91072699
     No wonder nobody comes here--it's too crowded. -Yogi Berra




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.3.95.970904093638.27174B-100000>