Re: Firewall hits from websites

From: Jason Kirk (usenet@captain.custard.org)
Date: 03/17/03

  • Next message: Casey Schaufler: "Re: /etc/passwd file"
    From: Jason Kirk <usenet@captain.custard.org>
    Date: Mon, 17 Mar 2003 10:51:10 -0600
    
    

    Jem Berkes wrote:
    >>The odd thing is that these hits originate
    >>from a website that I happen to be reading at the time. Normally only
    >>appear once from that site and not on subsquent (or indeed previous)
    >>visits. Is this normal behaviour or is there something more complex
    >>going on.
    >
    >
    > With state based firewalls (like netfilter/iptables on 2.4) what can happen
    > is that when packets arrive later than expected from a remote site, the OS
    > no longer recognizes the packets as related to any connection and logs
    > them.
    >
    > I see this frequently on my mail server. There are lots of packets from
    > hotmail servers shown in my logs, probably because the sites are sluggish
    > and netfilter is logging packets that arrive late from the site.
    >

    I would have thought that a late packet would have been expected on the standard
    port 80 where as these hits seem to be coming from port 33270.

    -Jason


  • Next message: Casey Schaufler: "Re: /etc/passwd file"

    Relevant Pages

    • Re: OT .. Road Warrior communications question
      ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
      (alt.guitar.bass)
    • Re: OT .. Road Warrior communications question
      ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
      (alt.guitar.bass)
    • Re: OT .. Road Warrior communications question
      ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
      (alt.guitar.bass)
    • Re: OT .. Road Warrior communications question
      ... address (your computer, the mail server, a website, etc). ... A whole bunch of packets of data are hitting ... The packets addressed to port 80 ... packets into a black hole. ...
      (alt.guitar.bass)
    • Re: OT .. Road Warrior communications question
      ... Each packet also includes a port number, which is used to direct the packet to the proper program at the destination computer. ... A whole bunch of packets of data are hitting your computer one right after another. ... The packets addressed to port 110 to go to your e-mail software. ... Likewise, at the mail server receiving the packets, it knows the return address of the computer sending a packet. ...
      (alt.guitar.bass)