Re: Interesting firewall log

From: Michael Heiming (michael+usenet@heiming.de)
Date: 12/08/02


From: Michael Heiming <michael+usenet@heiming.de>
Date: Sun, 08 Dec 2002 11:32:52 +0100

ynotssor <ynotssor> wrote:

>
>
> Michael Heiming wrote:
> [...]
>> Looks like someone scanning for www server/proxy server, not
>> uncommon, but the ipt_unclean looks strange, originates by:
>> /usr/src/linux/net/ipv4/netfilter/ipt_unclean.c
>>
>> If someone has some more insight about what happend, I would be
>> thankfull to hear.
>
> It's srhst13.yahoo.com for whatever reason; probably an ECN issue?

Thx, that might be the reason, had to disable it (tcp_ecn) for some
reasons, not long ago. Just strange that someone looks at all those
ports, commonly used for http/http-proxy.
 
>http://www.geocrawler.com/mail/thread.php3?subject=Why+all+these+unclean+packets%3F&list=225

Not applicable, I'm running 2.4.20 and ipt_unclean.c looks like like,
everything and more from this patch, has been build in.

Thx

Michael Heiming

-- 
Remove +SIGNS, if you expect an answer