LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 02-09-2002, 07:12 AM   #1
chens_83
Member
 
Registered: Dec 2001
Location: Adelaide , South Australia
Distribution: redhat 7.2, Debian , OpenBSD
Posts: 123

Rep: Reputation: 15
unknown messages


i was just wondering what this message means that i am receiving on my Mandrake 8.1 machine
It would be great if anyone could answer this question

auditin=ppp0 out= mac= src=147.102.35.52 dst=61.9.133.9 len=40 tos=0*00 prec=0*00 id=39426 proto=tcp spt=21 window=1028 res=0*00 syn fin urgp=0

it would be really cool if someone could break down this message as i am receiving it about every 6 or so hours and i am not sure what is exactly going on..thanks
 
Old 02-09-2002, 10:16 AM   #2
Malicious
Member
 
Registered: Jan 2002
Location: Galveston Island
Distribution: suse, redhat
Posts: 208

Rep: Reputation: 30
Are you running a firewall of some kind? This looks like a message that would be logging either an error or an attack.

auditin=ppp0 device being audited?
out=
mac=
src=147.102.35.52 source ip of the message
dst=61.9.133.9 destination of the msg
(one of these is probably your ip address)
len=40 length of message
tos=0*00
prec=0*00
id=39426
proto=tcp tcp message
spt=21 port 21 (ftp)?
window=1028
res=0*00
syn
fin
urgp=0

My best guess would be that someone at "src" is trying to ftp to "dst". I've seen this on cable/dsl ISPs where they attempt to find out if their users are running "illegal" servers of any kind.

By the way 147.102.35.52 is thais.cs.ece.ntua.gr
and 61.9.133.9 is CPE-61-9-133-9.vic.bigpond.net.au
 
Old 02-09-2002, 10:20 AM   #3
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
yeah, someone's trying to telnet (or atleast get in via the telnet port) into your machine. but you've not got telnet enable, so that's fine.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
what does messages suppressed in /var/log/messages mean saavik Linux - Networking 2 05-07-2008 02:31 PM
Redirecting the kernel messages to file other than /var/log/messages jyotika_b83 Linux - General 3 04-28-2005 06:39 PM
/var/log/messages full of these messages. Should I be concerned? mdavis Linux - Security 5 04-16-2004 10:08 AM
syslog and firestarter - log messages to another file than messages mule Linux - Newbie 0 08-07-2003 03:35 AM
Red Hat 8 - Unknown Error messages and accidental chmod tawsie Linux - Distributions 2 01-22-2003 05:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration