LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-22-2003, 04:35 AM   #1
PcHammer
Member
 
Registered: Jan 2001
Location: Ljubljana Slovenija
Distribution: Slackware
Posts: 70

Rep: Reputation: 15
portsentry log


I'm geting this portsentry logs on my firewall pc:
portsentry[186]: attackalert: Connect from host: 0.0.0.0/0.0.0.0 to UDP port: 67

I can not find out witch pc is doing this, is there any way to find this out ??? The time interval is around 5min. I think it is a pc trying to get ip from dhcp server but i'm not sure if this.
If any one has any idea pls let me know.


regards , pchammer
 
Old 01-22-2003, 05:31 AM   #2
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
for dhcp to work the client sends out a broadcast looking for a server. This is normal.
 
Old 01-25-2003, 11:42 AM   #3
PcHammer
Member
 
Registered: Jan 2001
Location: Ljubljana Slovenija
Distribution: Slackware
Posts: 70

Original Poster
Rep: Reputation: 15
That is ok if they are looking for a DHCP server but I don't use dhcp so i need to determine witch MAC address it uses.

regards, pchammer
 
Old 01-25-2003, 12:19 PM   #4
Darin
Senior Member
 
Registered: Jan 2003
Location: Portland, OR USA
Distribution: Slackware, SLAX, Gentoo, RH/Fedora
Posts: 1,024

Rep: Reputation: 45
tcpdump when it's happening, you should see the ARP broadcast with the source MAC.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
portsentry skoot Linux - Security 18 11-21-2005 06:29 AM
how to change notification email for portsentry and how to test portsentry roorings Linux - Security 1 11-04-2003 10:36 AM
PortSentry mikesvx1 Linux - Security 5 12-20-2001 01:52 AM
portsentry Jase Linux - Security 1 07-24-2001 07:49 AM
portsentry Dallam Linux - Security 5 07-12-2001 05:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration