Networking Forums

Networking Forums > Computer Networking > Linux Networking > Problem to understand the meaning of a log of ShoreWall

Reply
Thread Tools Display Modes

Problem to understand the meaning of a log of ShoreWall

 
 
didou
Guest
Posts: n/a

 
      12-14-2005, 10:29 PM
My ShoreWall generate lots of message (more than 1 per second !) in the
file /var/log/messages

Can any body explain to me what mean this message

Dec 15 01:22:50 lns-th2-4f-XX-YY-ZZ-TT kernel:
Shorewall:net2allROP:IN=eth1 OUT=
MAC=00:07:cb:00:00:ff:00:07:cb:1e:65:dc:08:00 SRC=207.226.112.34
DST=XX.YY.ZZ.TT LEN=53 TOS=0x00 PREC=0x00 TTL=120 ID=14859 PROTO=UDP
SPT=7871 DPT=14809 LEN=33

XX.YY.ZZ.TT is the ip of my computer on interner

 
Reply With Quote
 
 
 
 
Bit Twister
Guest
Posts: n/a

 
      12-15-2005, 12:10 AM
On 14 Dec 2005 15:29:21 -0800, didou wrote:
> My ShoreWall generate lots of message (more than 1 per second !) in the
> file /var/log/messages
>
> Can any body explain to me what mean this message
>
> Dec 15 01:22:50 lns-th2-4f-XX-YY-ZZ-TT kernel:
> Shorewall:net2allROP:IN=eth1 OUT=
> MAC=00:07:cb:00:00:ff:00:07:cb:1e:65:dc:08:00 SRC=207.226.112.34
> DST=XX.YY.ZZ.TT LEN=53 TOS=0x00 PREC=0x00 TTL=120 ID=14859 PROTO=UDP
> SPT=7871 DPT=14809 LEN=33


Shorewall rule net2all dropped the connection attempt from
207-226-112-34.btnaccess.net (207.226.112.34) to your firewall.
The attempt was to port 14809 using the UDP protocol.

It can be instructive to read each of the files found in /etc/shorewall.

For extra points
http://www.shorewall.net/Documentation.html

Want to play with the shorwall tables throug gui, install webmin.
Then connect with https:localhost:10000
 
Reply With Quote
 
didou
Guest
Posts: n/a

 
      12-16-2005, 03:05 PM
thanks,

my computer seems to be object of an attack !

more than 1 try by second....

 
Reply With Quote
 
Bit Twister
Guest
Posts: n/a

 
      12-16-2005, 03:35 PM
On 16 Dec 2005 08:05:50 -0800, didou wrote:

> my computer seems to be object of an attack !


Attack is a little harsh. I would call it normal attempts by script kiddies.

I used to watch them just to see what contries they came from.

Now I just put the ports in /etc/shorewall/blacklist when they are
frequent or a new piece of malware starts probing a new port.

 
Reply With Quote
 
didou
Guest
Posts: n/a

 
      12-16-2005, 10:30 PM
the SRC and ID (ip and port) change at each line !

may it be a consequence of the usage of mldonkey (peer-to-peer) ?

(to stop mldonkey don't change anything)

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Shorewall and MySQL problem tj Linux Networking 10 02-12-2007 06:02 PM
Bridge Problem ! don't understand anuthing ! buzzer Linux Networking 0 07-14-2005 03:27 PM
Routing, Shorewall, Mldonkey (?) problem. Panivino Linux Networking 0 06-08-2005 01:08 PM
Problem with Linux 2.6.4 DSL Gateway using Iptables and Shorewall Jochen Demmer Linux Networking 9 09-20-2004 04:09 PM
shorewall and ULOG problem Ian Colley Linux Networking 0 12-26-2003 04:22 PM



1 2 3 4 5 6 7 8 9 10 11