LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-30-2004, 06:46 AM   #1
Bjorkli
Member
 
Registered: Jul 2003
Location: Norway
Posts: 65

Rep: Reputation: 15
Question Log entry question. What did Microsoft do with my Linux kernel?


I have Fedora Core 1 installed, and to make myself better at security I have startet to read the logs. But the following log piece I have no idea what means.

(Taken from log called messages)
Quote:
Nov 29 22:02:39 linux kernel: IN=eth0 OUT= MAC=00:0d:56:57:23:45:00:04:ed:05:0f:19:08:00 SRC=65.54.194.118 DST=192.168.1.103 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=50943 PROTO=TCP SPT=80 DPT=29082 WINDOW=9300 RES=0x00 RST URGP=0
Nov 29 22:02:39 linux kernel: IN=eth0 OUT= MAC=00:0d:56:57:23:45:00:04:ed:05:0f:19:08:00 SRC=65.54.194.118 DST=192.168.1.103 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=52479 PROTO=TCP SPT=80 DPT=29081 WINDOW=9300 RES=0x00 RST URGP=0
Wondering who 65.54.194.118 was, I did a "whois 65.54.194.118", and got the following
Quote:
[root@linux log]# whois 65.54.194.118
[Querying whois.arin.net]
[whois.arin.net]

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
etc etc
Soo... Now I wonder what this log entry means I have not seen this one before, and searching this forum for it did not help me. What does Microsoft want with my Linux machine?
 
Old 11-30-2004, 09:11 AM   #2
b0uncer
LQ Guru
 
Registered: Aug 2003
Distribution: CentOS, OS X
Posts: 5,131

Rep: Reputation: Disabled
is Redmond really a city? I thought something else...
 
Old 11-30-2004, 10:05 AM   #3
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
It's a request via port 80 from 65.54.194.118 to 192.168.1.103. So you have port 80 open. Are you running an internet server? It may not be anything sinister at all, as many organisations including M$ run crawlers, spiders etc. If port 80 is open then they will investigate to see if they get a response to a http request. If you are running a router it also suggests that it is forwarding port 80 as well. If you don't run a service on port 80 then close it and also stop forwarding on the router.

Last edited by TigerOC; 11-30-2004 at 10:06 AM.
 
Old 11-30-2004, 10:27 AM   #4
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Quote:
Originally posted by TigerOC
It's a request via port 80 from 65.54.194.118 to 192.168.1.103. So you have port 80 open. Are you running an internet server?
Wrong way. The *source* port is 80 meaning that this is a response, not a request.

Bjork, did you recently try to vist any MS sites? The logs you posted are created by violations of your IPTABLES ruleset. The specific violations would seem to indicate that your system requested a web page from a Microsoft server, but your firewall blocked the response packets.
 
Old 11-30-2004, 02:32 PM   #5
Bjorkli
Member
 
Registered: Jul 2003
Location: Norway
Posts: 65

Original Poster
Rep: Reputation: 15
Um. Yeah. Running a family web server on the Linux (not used much), but it is not on port 80 though... It is using port 8081 or something. Port 80 on my machine is closed on my Linux server (well. Firestarter says so anyway)

On the same router, I have a XP home computer connected, with Apache web server using port 80 (backup copy in case something happens to my Linux machine). Maybe the router got confused or something and sent the packet to the linux instead of the XP machine. At 02:39... Was sleeping then... Anyway... Must have been a crawler or something. The Linux box still works (as allways), and hopefully it stays like that...

Anyway... wish the logs weren't so cryptic.. My first gues would not have been it was a firewall warning message. Looks like my XP have been infected by something again. The router lights up all the time, and something is downloading to my machine, and I have no idea where to check what is downloading. Hopefully it is just windows update...

But thanks for the replies. Now I know what a firewall message looks like.
 
Old 11-30-2004, 03:12 PM   #6
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
If you have an XP box running on the network there is your answer. XP sends surreptitious reports back to Redmond if you didn't already know that.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Log File entry Mclewson Linux - Security 1 06-29-2005 09:21 AM
suspicious entry in /var/log/auth.log buehler Linux - Security 5 04-27-2005 05:11 PM
Interesting Microsoft Knowledge base entry leadazide General 8 01-28-2005 11:52 AM
Apache log entry- what is this? ScreeminChikin Linux - Software 2 09-18-2003 02:28 AM
iptables log entry??? bulliver Linux - Security 2 02-15-2003 10:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:01 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration