Re: Why does an ip resolving to Genuity appear in my /var/log/wtmp?
From: Barry Margolin (barmar@genuity.net)
Date: 01/23/03
- Next message: Alun Jones: "Re: getting around Ken Thompson's compiler Trojan"
- Previous message: mr.e: "Re: Why does an ip resolving to Genuity appear in my /var/log/wtmp?"
- In reply to: mr.e: "Re: Why does an ip resolving to Genuity appear in my /var/log/wtmp?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Barry Margolin <barmar@genuity.net> Date: Thu, 23 Jan 2003 02:07:11 GMT
In article <oIGX9.77150$ej1.30681@news02.bloor.is.net.cable.rogers.com>,
mr.e <anjin@rogers.com> wrote:
>Barry Margolin wrote:
>> In article <G5nX9.130611$pDv.86887@news04.bloor.is.net.cable.rogers.com>,
>> mr.e <anjin@rogers.com> wrote:
>>
>>>sez it all doesn't it?
>>>over to you Barry
>>
>>
>> What IP? Maybe one of your users comes from one of our DSL customers.
>>
>Nope. Home lan. Fresh install of Mandrake 9. The box in question is
>sitting behind a strict ipchains firewall, and the ip 8.27.1.64 showed
>up in /wtmp within minutes of this box being connected. Checking the
>firewall box shows the ip 8.0.0.0 associated with the non-root users
>(all 2 of them) on the system.
>I'm not a happy camper.
Although we own the 8.0.0.0/8 address block, we're not actually using it as
far as I know, except possibly on some internal test networks. It's just a
network we've had assigned to us since the early days of the Internet
(Genuity used to be Bolt, Beranek, & Newman, where much of the original
Arpanet and Internet development was done).
I don't see any way a remote system could have successfully logged into
your system from that address, since there are no routes for any 8.x.x.x
addresses on the Internet. The only explanations I can think of are that
your ISP is using those addresses internally (*bad* ISP), or you're using
them on your home LAN (*bad* you).
What happens if you ping or traceroute to that address? How far does the
traceroute get?
-- Barry Margolin, barmar@genuity.net Genuity, Woburn, MA *** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups. Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.
- Next message: Alun Jones: "Re: getting around Ken Thompson's compiler Trojan"
- Previous message: mr.e: "Re: Why does an ip resolving to Genuity appear in my /var/log/wtmp?"
- In reply to: mr.e: "Re: Why does an ip resolving to Genuity appear in my /var/log/wtmp?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|