Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 16 Jun 2002 11:26:29 -0400
From:      "Joe & Fhe Barbish" <barbish@a1poweruser.com>
To:        "FBSDQ" <questions@FreeBSD.ORG>
Subject:   IPFW blocking auto-spawned web pages
Message-ID:  <MIEPLLIBMLEEABPDBIEGAEOBCCAA.barbish@a1poweruser.com>

next in thread | raw e-mail | index | archive | help
I exclusively use Advanced stateful IPFW rules check-state - keep-state
rules. I just converted from using an modem dial up ISP with user 
ppp -nat  to cable modem with ipfw internal divert natd statement added
to my ipfw rule file. Some thing strange but good has started to happen.
The last rule in my rules file is an   deny log all from any to any  so
 I can see all the packets that fall through my rules file without a 
match. Since I changed my ipfw rules file by just adding the single
   divert natd  statement my last rule to log every thing that has not 
matched any rules has starting logging a lot of outbound port 80 
packets. This has bothered me as I though my system was compromised.  
I went so far as to reinstall version 4.5 from scratch again and 
reinstall a clean WINME system on one of the LAN machine I was using 
for testing just to ensure I did not have any spy ware or Trojans, or 
backdoor virus on my system. Nothing helped, these packets just keep 
showing up in the ipfw log. The target ip address does not repeat in 
most cases from day to day. In frustration I tried putting the target
ip address from these denied outbound packets directly in the http URL 
of my browser and bingo I pulled up a web page. To my great surprise 
every one of those denied packets stopped by my  Advanced stateful IPFW
firewall turns out to be an auto-spawned web page that was buried in 
the original web page I was looking at.   The ipfw man info does not 
document this behavior.  The blocking of those annoying  auto-spawned 
web pages by the ipfw firewall is a very desirable ability and seems to
be a side effect of exclusively using Advanced stateful IPFW 
check-state - keep-state rules.

Has anybody else out there seen this behavior?




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?MIEPLLIBMLEEABPDBIEGAEOBCCAA.barbish>