LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 12-10-2004, 04:42 PM   #1
spikeygg
Member
 
Registered: Dec 2004
Location: America
Distribution: Ubuntu
Posts: 32

Rep: Reputation: 0
Question Lots of Martians in my Syslog


Hello All,

I've recently been getting lots of this error in my syslog:
Code:
Dec 10 14:38:46 spikey kernel: martian source 24.117.175.67 from 127.0.0.1, on dev eth0
Dec 10 14:38:46 spikey kernel: ll header: 00:40:95:d0:04:f6:00:08:20:cb:08:8c:08:00
Dec 10 14:49:48 spikey kernel: martian source 24.117.175.67 from 127.0.0.1, on dev eth0
Dec 10 14:49:48 spikey kernel: ll header: 00:40:95:d0:04:f6:00:08:20:cb:08:8c:08:00
These messages seem to come in about every 10 or 20 minutes over the course of several hours, then there will be a gap of a few hours then it starts up again. The weird thing is the 24.117.175.67 is my IP and the first set of numbers after the header is the mac address to my external interface. I thought the packets were coming from my own machine, at first. I found a few people on this forum who have seen similar issues, but I haven't found any who have resolved it. It sounds like these "martian source" errors could be one of two things:
1. Misconfigured Network
2. Malicious Attacks from spoofed IP addresses.

I've been trying to figure out which one it is because if it is a network configuration issue I want to fix it. If it's a hacker, I'd like to know too. Recently, I've found a tool that is most useful. tcpdump. I ran it looking for stuff coming in from 127.0.0.1 and it spit out stuff like this:
Code:
14:49:48.917605 localhost.http > 24-117-175-67.cpe.cableone.net.1012: R 0:0(0) ack 836894721 win 0
15:09:21.954525 localhost.http > 24-117-175-67.cpe.cableone.net.prospero-np: R 0:0(0) ack 988610561 win 0
So, I see an interesting thing in this log: ".1012" and ".prospero-np", this makes me think that it's actually hackers. What do the experts on this forum have to say?

Thanks for any input.

-Greg
 
Old 12-10-2004, 04:54 PM   #2
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 46
You're getting spoofed packtes looks like, which may or may not (likely not) be indicative of a break in attempt.

Try adding this to your firewall script:
Code:
echo 1 >> /proc/sys/net/ipv4/conf/*/rp_filter
This will stop things like this most likely. rp_filter disallows packets from localhost on the ethernet interfaces and the like.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Getting lots of strange messages during reboot and in my syslog? M$ISBS Linux - Security 6 07-30-2005 09:33 PM
Need lots of help KramarDanIkabu Linux - Newbie 8 07-13-2005 01:39 PM
Enabling martians... fodavis Linux - Networking 2 04-19-2005 08:13 AM
Lots of WMs khsater Linux - Distributions 3 03-26-2005 10:12 PM
Need lots of help! :) pointsplat Linux - General 2 11-28-2002 04:03 PM


All times are GMT -5. The time now is 12:09 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration