Re: help with analysis of firewall log

From: Ashok Aiyar (aiyar@ebv.mimnet.northwestern.edu)
Date: 02/27/02


From: Ashok Aiyar <aiyar@ebv.mimnet.northwestern.edu>
Date: 27 Feb 2002 16:07:34 GMT

On Wed, 27 Feb 2002 14:50:36 GMT,
    Hal Burgiss (hal@burgiss.net) wrote:
>> port attempts protocol explanation
>> 8 290 udp ??
>
> My guess is this one is actually ICMP type 8, and not a port. I've seen
> some log analyzers that do this.

Well, the raw iptables log indicates it is UDP port 8. I don't have
iptables configured to log icmp. I have attached a sample entry below:

Feb 22 17:06:31 ebv kernel: fw filter: IN=eth0 OUT=
MAC=ff:ff:ff:ff:ff:ff:00:00:39:d0:40:e1:08:00
SRC=192.168.1.103 DST=255.255.255.255 LEN=196 TOS=0x00
PREC=0x00 TTL=128 ID=278 PROTO=UDP SPT=8 DPT=8 LEN=176

All 290 happened consecutively, and came from the same IP address.
Strange ...
 
>> 33486-33524 39 udp
>
> Traceroute?

Definitely. I agree. I haven't been able to figure out what the
others are, and couldn't find descriptions on SANS, which was the
reason for my post ...

Cheers,
Ashok

-- 
Ashok Aiyar
RLU #51601



Relevant Pages

  • Re: Blocked incoming ICMP, getting outgoing ICMP [3] Destination Unreachable
    ... ICMP Type 30 was an experimental protocol - see RFC1393. ... The real LBL traceroute uses UDP, ... defaults to probing port 80. ... ACK/RST TCP packet (see my reply in the thread "Please help me interpret ...
    (comp.security.firewalls)
  • Re: Ports to block for CheckPoint Firewall?
    ... > did not know we left port 1434/UDP open in the firewall, ... in/out on port 1434. ... Allow ICMP type 3 incoming; ... Block UDP NetBIOS 135-139 in/out ...
    (comp.security.firewalls)
  • Dead Thread: New piece of spyware?
    ... to all posters PLEASE do some homework before posting. ... port and include packet traces. ... get the ICMP type and code information. ...
    (Incidents)
  • Re: ICMP on port 3
    ... ICMP doesnt use ports, what made you think it was port 3? ... with ICMP Type or Code. ... Regards, ...
    (Security-Basics)
  • Re: help with analysis of firewall log
    ... > increase in port 139 connection attempts. ... > port attempts protocol explanation ... some log analyzers that do this. ... Connection tracking can also give false positives where a packet might ...
    (comp.os.linux.security)