Re: strange tcpdump traffic
From: David (thunderbolt01_at_netscape.net)
Date: 02/13/04
- Next message: Nomen Nescio: "running gnutella, leaving ports open when not in use"
- Previous message: Doug Holtz NOSPAM in adress: "Re: Security on Networked Copier"
- In reply to: Michael Wimmer: "strange tcpdump traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 13 Feb 2004 15:19:43 GMT
Michael Wimmer wrote:
> Hi,
>
> we have problems with our internet connection so I look at the traffice
> at our gateway.
>
> There are many requests from a specific address to our internal machine
> running msde (3a). Currently the database is not supposed to be accessed
> from outside.
>
> Could anybody tell me if I should be concerned about this an what which
> actions I should take?
>
> 09:45:37.291046 209.248.158.74.nw.nuvox.net.48760 >
> xxx18.xxx.at.ms-sql-s: . ack 1 win 8760 (DF)
> 09:45:37.293020 209.248.158.74.nw.nuvox.net.48760 >
> xxx18.xxx.at.ms-sql-s: . ack 128 win 8634 (DF)
> 09:45:37.293342 209.248.158.74.nw.nuvox.net.48760 >
> xxx18.xxx.at.ms-sql-s: F 166:166(0) ack 128 win 8634 (DF)
>
> 09:46:41.931797 209.248.158.74.nw.nuvox.net.29065 >
> xxx18.xxx.at.ms-sql-s: . ack 128 win 8634 (DF)
> 09:46:41.931866 209.248.158.74.nw.nuvox.net.29065 >
> xxx18.xxx.at.ms-sql-s: F 168:168(0) ack 128 win 8634 (DF)
> 09:46:41.931932 209.248.158.74.nw.nuvox.net.30628 >
> xxx18.xxx.at.ms-sql-s: S 3969673928:3969673928(0) win 8192 <mss 1460> (DF)
Below it looks like your system replied to the request. If the
database system isn't suppose to be accessed from the internet
them I would say your firewall/gateway is misconfigured somewhere.
Possibly at ports:
ms-sql-s 1433/tcp #Microsoft-SQL-Server
ms-sql-s 1433/udp #Microsoft-SQL-Server
> 09:46:41.932046 xxx18.xxx.at.ms-sql-s >
> 209.248.158.74.nw.nuvox.net.29065: . ack 169 win 17352 (DF)
> 09:46:41.932270 xxx18.xxx.at.ms-sql-s >
> 209.248.158.74.nw.nuvox.net.30628: S 10918107:10918107(0) ack 3969673929
> win 17520 <mss 1460> (DF)
>
> I am not the one who set up this machine nor I am in charge of
> maintaining it, but I am the only one available right now. So please
> apologize if this question reveals some lack of understanding.
-- Confucius: He who play in root, eventually kill tree. Registered with The Linux Counter. http://counter.li.org/ Slackware 9.1.0 Kernel 2.4.24 SMP i686 (GCC) 3.3.2 Uptime: 38 days, 20:46, 2 users, load average: 1.14, 1.20, 1.0
- Next message: Nomen Nescio: "running gnutella, leaving ports open when not in use"
- Previous message: Doug Holtz NOSPAM in adress: "Re: Security on Networked Copier"
- In reply to: Michael Wimmer: "strange tcpdump traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|