LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-22-2008, 03:39 AM   #16
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897

Quote:
Originally Posted by investmentbnker75 View Post
But doesnt the SRC=172.xx.xx.xx DST=216.xxx.xxx.xxx line mean that the src of the ssh connection is the server thats locking up (172.ip) and that its trying to reach the destination IP 216.?
No. Read Chort's first response. This packet is outbound, but, looking at the accompanying data, you can see that ACK is on for this packet. That is, this is the ACK packet out of a SYN/ACK handshake sequence. In other words, this is an outbound packet in an incoming connection initiated from the other end.

It is not clear why you will not look up the owner of the 216.xxx.xxx.xxx IP address. If you are having some miscreant trying to login via ssh, that is your culprit.
 
Old 07-22-2008, 01:28 PM   #17
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Quote:
Originally Posted by chort View Post
You should specify which BSD, because OpenBSD has had strong randomization in source ports and IDs for quite some time.

OpenBSD
MACOSX
FreeBSD
NetBSD



http://www.securiteam.com/securityre...PP0H0UNGW.html
 
Old 07-25-2008, 01:38 AM   #18
investmentbnker75
Member
 
Registered: Oct 2007
Location: Eastern Seaboard
Distribution: CentOS
Posts: 162

Original Poster
Rep: Reputation: 15
The other IP (216.xxx) is a nat server in another dc where other servers are.
 
Old 07-25-2008, 02:57 AM   #19
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by nx5000 View Post
But they at least used randomization. Every production version of Linux that I've taken a tcpdump from hasn't used any IP Id randomization at all, they all increment by 2.

Edit: This was fixed less than two weeks later. The OpenBSD team based their fix off the one for DragonflyBSD, but did a lot of additional testing rather than rush to get a band-aid in place. There are a lot of other commits over the next few months that further strengthened the randomization in various networking components (read the CVS commit message e-mail archive).

Quote:
CVSROOT: /cvs
Module name: src
Changes by: deraadt@cvs.openbsd.org 2008/02/28 20:37:26

Modified files:
sys/netinet : ip_id.c

Log message:
replacement algorithm. initialize a 64K-short buffer using Durstenfeld
shuffle. Upon allocation, swap-permute the new value to a random slot in
the 0..32K-1 th entry of the buffer as we move forward, ensuring randomness
but also satisfying the non-repeating property we need. Also avoid the value
of 0, since IP ID's of 0 are special. Inspired by Dillon's implementation.
We believe this is easier to read though, initializes with less bias, handles
the ID of 0 properly, and wins speed tests.
Thanks a lot to mcbride and djm for doing a bunch of statistical and speed
analysis, and comments from nordin
ok mcbride djm

Last edited by chort; 07-25-2008 at 03:21 AM. Reason: more info
 
Old 07-25-2008, 02:58 AM   #20
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by investmentbnker75 View Post
The other IP (216.xxx) is a nat server in another dc where other servers are.
So check the logs there to see what host is trying to open an ssh connection to your server.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
cPanel/WHM Network Server Issue RobertNikic Linux - Networking 1 06-24-2008 01:27 AM
cifs locking issue slackamp Linux - Software 0 03-19-2007 10:24 AM
Help with locking down network threegig Linux - Networking 4 05-17-2006 11:14 AM
Interesting Issue - File Locking czelaya Linux - Networking 1 10-15-2005 05:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration