LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 03-31-2003, 11:57 AM   #1
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Real Washington
Distribution: Ubuntu, Debian, SuSE, UnSlung, Android
Posts: 1,819

Rep: Reputation: 46
Question martian source baffling me?


Here is the setup

Internet <--12.xx.xxx.xx --> Firewall box (192.168.10.1)<----------> Squid server (192.168.10.2)<------>LAN (192.168.0.0/24)

My squid server doubles as a Domino server with the correct ports forwarded to and from it. Heres the catch.

In /var/log/messages on the firewall machine I have entries saying

Martian source - source 192.168.1.101 from 192.168.0.56 incoming int eth0

The way I read this is, that a packet came from the squid server claiming to be from the 1.101 address (I don't use that subnet) came in on the firewalls internal interface (x-over cable to squid server). Should I be worried? It sounds like packet spoofing, but I have protection against that in the firewall.
The firewall stands up to a port scan from the outside showing only the mail ports I forward as "open"..

Last edited by Pcghost; 03-31-2003 at 11:58 AM.
 
Old 03-31-2003, 12:08 PM   #2
bahamat
Member
 
Registered: Mar 2003
Distribution: Debian
Posts: 158

Rep: Reputation: 30
Well since the packet is aparently from 192.168.0.56 why not start there and see what may be causing it?

You might just find that you've got a gateway address typed in wrong.

As they say, don't attribute to malice that which can be adequately explained by stupidity. In other words, the cause is 9 times out of 10 harmless.
 
Old 03-31-2003, 01:01 PM   #3
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Real Washington
Distribution: Ubuntu, Debian, SuSE, UnSlung, Android
Posts: 1,819

Original Poster
Rep: Reputation: 46
I thought that as well. So I checked the mail/squid server for log entries. I tracerouted 192.168.1.101 to see where it went. It ended up resolving to 12.124.170.61 . Strange, I checked the hosts files on both machines and there is no entry for this address. I port scanned it and it shows no ports open, or like me it's dropping icmp requests. How is it tracerouting to an internal address like 192.168.1.101 could lead me to an external address with no entry in the local hosts files and no mension of it in the firewall?

Oh I should also mension that 192.168.0.56 is the internal/LAN side address of the Squid server.

Last edited by Pcghost; 03-31-2003 at 01:03 PM.
 
Old 04-01-2003, 09:43 PM   #4
bastard23
Member
 
Registered: Mar 2003
Distribution: Debian
Posts: 275

Rep: Reputation: 30
Pcghost,
How often do they happen? Run 'tcpdump -w 101.tcp -s0 host 192.168.1.101' on the firewall to capture the packets. Use 'tcpdump -r 101.tcp' to look at it (ethereal is better if you can transfer the file to a machine with X). At least you'll know what is being sent. I suspect that the ISP is using some similar adresseses. Technically, they "can" work on the same "network" (aka your ISP's), but not at their border routers (the internet).

I would recommend dropping this at your border router (you firewall box or your router).

Hope that helps,
chris
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
martian source from my own IP? yapp Linux - Security 4 03-30-2005 07:36 PM
martian source messages win32sux Linux - Security 2 08-26-2004 06:33 PM
martian source saavik Linux - Networking 0 07-02-2003 03:47 AM
what does martian source mean? saavik Linux - Security 4 06-04-2002 09:34 AM
Martian source! Why now? Jon- Linux - Networking 1 03-05-2002 07:14 PM


All times are GMT -5. The time now is 12:37 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration