LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-10-2005, 04:56 PM   #1
baldmonk
LQ Newbie
 
Registered: May 2005
Posts: 7

Rep: Reputation: 0
how should i interpret this??


i got these lines on my /var/log/messages

Jun 10 14:41:53 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:10:b5:10:12:98:08:00 SRC=192.168.2.34 DST=192.168.2.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=28132 PROTO=UDP SPT=137 DPT=137 LEN=58

Jun 10 14:13:49 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=00:04:5a:4d:ff:0f:00:30:bd:09:b1:ac:08:00 SRC=24.81.240.124 DST=192.168.2.14 LEN=48 TOS=0x10 PREC=0x00 TTL=110 ID=62013 DF PROTO=TCP SPT=2028 DPT=21 WINDOW=16384 RES=0x00 SYN URGP=0
Jun 10 14:13:52 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=00:04:5a:4d:ff:0f:00:30:bd:09:b1:ac:08:00 SRC=24.81.240.124 DST=192.168.2.14 LEN=48 TOS=0x10 PREC=0x00 TTL=110 ID=62521 DF PROTO=TCP SPT=2028 DPT=21 WINDOW=16384 RES=0x00 SYN URGP=0

well the 196.168.2.34 is my sister's computer internal ip within the a router, does this mean my sister computer is pinging mine??

and the other ip.. was that just an attempts.. or did he/she successful got into my computer

im using arno iptatbles script...

monk
 
Old 06-10-2005, 05:21 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
I guess your sister's running Windows. It looks it's her computer trying to find shared data. If you don't have Samba running it finds noting.

Second attempt is more interesting. It's an FTP access (or just try of it). I don't know the scripts you're using, but they usually print what was dropped. After all, if you don't run an FTP server, it will end as the attempt to get shared data.
 
Old 06-10-2005, 05:32 PM   #3
baldmonk
LQ Newbie
 
Registered: May 2005
Posts: 7

Original Poster
Rep: Reputation: 0
thanks for answering...

i dont have any ftp running.. so i guess it's ok..

monk
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to interpret images using C++? vivekr Programming 8 11-18-2005 08:40 AM
Interpret this simple C code Chase_G Programming 4 04-29-2005 09:07 AM
How to interpret backtrace (gdb) jnusa Programming 1 12-06-2004 09:16 AM
I need Help to interpret this time format unixfreak Linux - Newbie 7 08-03-2004 12:13 AM
Interpret ICMP packets SaTaN Linux - Networking 1 01-20-2004 10:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration