Re: Firewall log

From: David (thunderbolt01_at_netscape.net)
Date: 07/30/03

  • Next message: David: "Re: Linux and security"
    Date: Wed, 30 Jul 2003 19:32:23 GMT
    
    

    BB wrote:
    >
    > The log:
    > Jul 29 08:14:48 linux kernel: TCP killed:IN=eth0 OUT=eth1 SRC=X.X.X.X
    > DST=66.93.144.242 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=42255 DF
    > PROTO=TCP SPT=1064 DPT=139 WINDOW=8192 RES=0x00 SYN URGP=0
    >
    > Jul 29 08:15:38 linux kernel: UDP killed:IN=eth0 OUT=eth1 SRC=X.X.X.X
    > DST=66.150.161.136 LEN=78 TOS=0x00 PREC=0x00 TTL=127 ID=45327
    > PROTO=UDP SPT=137 DPT=137 LEN=58
    >
    > For example, ip 66.93.144.242 is registered to ns1.derver2.com... The
    > interested port are 139 and 137... what about this?

    Those ports are used for Netbios which is a Windows protocol so
    you can drop ports 137:139 and not log it if you don't want you
    logs to fill up.

    -- 
    Confucius:  He who play in root, eventually kill tree.
    Registered with The Linux Counter.  http://counter.li.org/
    Slackware 9.0 Kernel 2.4.21 i686 (GCC) 3.3
    Uptime: 13 days, 14:32, 1 user, load average: 1.22, 1.14, 1.17
    

  • Next message: David: "Re: Linux and security"

    Relevant Pages

    • Re: What are these ports?
      ... >>properly it keeps the connection around long enough to make sure the close ... I do have MS NTP client turned off. ... > Since I am not using NetBios why does it seem that the ports are open? ... You will still be using NetBIOS locally even if you aren't using it over the ...
      (microsoft.public.windowsxp.network_web)
    • Re: Domain Controller port numbers
      ... Here is a list of ports... ... NetBIOS datagram service 138/udp ... Service overview and network port requirements for the Windows Server system ... > Windows cannot obtain the domain controller name for your computer ...
      (microsoft.public.windows.server.general)
    • RE: nc help needed.
      ... You can even get Netcat to listen on the NETBIOS ports that are probably ... user can run a program that will bind to the NETBIOS ports. ...
      (Security-Basics)
    • Re: Zone Labs Pro question
      ... NetBIOS is disabled but I'm still getting ... Can you tell me how I block outgoing TCP on ports ... > alerting function in the pro version allows for various levels of alerts. ...
      (comp.security.firewalls)
    • Re: Microsoft "Messenger Service"
      ... it is a NETBIOS functionality which means I must of had ... > one the Microsoft netbeui ports open. ... > home machine IP. ... > use NET SEND if the proper Microsoft ports 135-137 are not open. ...
      (comp.security.misc)