Re: A few odd outbound packets
From: James Wyatt (wyatt@attbi.com)Date: 03/30/02
- Next message: James Wyatt: "Re: MD5"
- Previous message: Nico Coetzee: "Re: virus extensions"
- In reply to: frankB: "A few odd outbound packets"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: James Wyatt <wyatt@attbi.com> Date: Sat, 30 Mar 2002 21:03:11 GMT
I did a reverse DNS lookup on the destination IP and came back with
ftp24c.newaol.com...it's using the TCP protocol so it is a connection
based exchange...any AOL programs on your system? The first packet you
have here is a SYN packet which is requesting a connection...the second
appears to be carrying a payload...My guess is that AOL is doing some
spyware stuff when you look at their page, use their email/news,
etc...If the ip stays static, I would just add a rule to deny ip any
64.12.168.202 log...and watch what happens...
frankB wrote:
> Every now and then I get a couple of strange outbound packets that are
> caught by IPTABLES - I only allow a few specific ports open for outbound
> and all inbound is only on established connections (machine is also behind
> a router).
>
> Mar 29 18:25:59 localhost kernel: IPTABLES TCP-OUT: IN= OUT=eth0
> SRC=192.168.1.250 DST=64.12.168.202 LEN=60 TOS=0x00 PREC=0x00 TTL=64
> ID=6144 PROTO=TCP SPT=33483 DPT=44483 WINDOW=5840 RES=0x00 SYN URGP=0
>
> Mar 29 18:26:39 localhost kernel: IPTABLES TCP-OUT: IN= OUT=eth0
> SRC=192.168.1.250 DST=64.12.168.202 LEN=60 TOS=0x00 PREC=0x00 TTL=64
> ID=6144 PROTO=TCP SPT=33485
>
> I don't see any pattern that relates to apps I'm running. Mostly it's just
> mail, web, news. I had a couple of these packets about a week ago, but
> nothing for the last few days. I read 1 post that suggested this could be
> a rootkit. I just ran chkrootkit 0.35, and everything came up negative.
>
> Any suggestions? Thanks.
>
>
- Next message: James Wyatt: "Re: MD5"
- Previous message: Nico Coetzee: "Re: virus extensions"
- In reply to: frankB: "A few odd outbound packets"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|