funny packets

From: Andre Goeree (abgoeree@uwnet.nl)
Date: 03/28/01


From: "Andre Goeree" <abgoeree@uwnet.nl>
Date: Wed, 28 Mar 2001 00:29:07 +0200
To: freebsd-security@freebsd.org

Hello,

While CVSuppin' ports i caught some strange packets:

Mar 27 23:29:38 mandark /kernel: ipfw: 3900 Deny TCP 195.25.44.186:4828 213.227.128.244:4662 in via tun0
Mar 27 23:29:38 mandark /kernel: ipfw: 3900 Deny TCP 195.25.44.186:4828 213.227.128.244:4662 in via tun0
Mar 27 23:35:38 mandark /kernel: ipfw: 3900 Deny TCP 195.25.44.186:1075 213.227.128.244:4662 in via tun0
Mar 27 23:35:38 mandark /kernel: ipfw: 3900 Deny TCP 195.25.44.186:1075 213.227.128.244:4662 in via tun0

Notice the time between the messages, exactly 6 min.
195.25.44.186 was/is not resolvable.
Any ideas?

--Andre.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Connections to ports > 1024
    ... Subject: Connections to ports> 1024 ... > DNS server, like BIND?) ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Connection attempts (& active ids)
    ... > Well, by listening on more ports, you're just making yourself a more ... icmp echo is blocked (ipfw deny) ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: blocking RFC 793 ports 1024-49151
    ... > have been hitting the ports with strange packets, perhaps seeking to ...
    (comp.security.unix)
  • Re: 31337
    ... >> Just to add some extra info I'd like to say that I've seen nmap reporting ... >> such open ports a lot of times while doing port scans on my machines and ... > don't think you should be seeing any false positives. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Anti-Virus for SMTP
    ... > Check amavis in the ports. ... I'm talking about "the complete scanning" solution, ... >>I have a FreeBSD 4.2 e-mail server running Sendmail. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)