LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-12-2006, 08:20 AM   #1
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Rep: Reputation: 30
spoofs


Code:
Sep 12 12:54:27 argo BOGON_SPOOF: IN=eth0 OUT= MAC=00:40:f4:7a:58:25:00:09:5b:b0:3c:a2:08:00  SRC=172.16.175.247 DST=192.168.0.2 LEN=60 TOS=00 PREC=0x00 TTL=47 ID=53445 CE DF PROTO=TCP SPT=36110 DPT=9091 SEQ=3315513394 ACK=0 WINDOW=5840 SYN URGP=0
As you see the ip trying to connect to my tor server is a reserverd one (172.16.0.0/12) because i have plenty of it in my iptables logs is anything more i can do to prevent this ?
Thanks !
 
Old 09-12-2006, 02:21 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
As you see the ip trying to connect to my tor server is a reserverd one (172.16.0.0/12)
No it ain't a reserved one.
 
Old 09-13-2006, 09:57 AM   #3
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Original Poster
Rep: Reputation: 30
To me it looks like a IANA reserverd address:
http://www.iana.org/assignments/ipv4-address-space
Or to this one :http://www.completewhois.com/bogons/...s-cidr-all.txt
 
Old 09-13-2006, 12:50 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm. I'm pretty use I saw some spanish ISP nfo, but OK, I spose I queried for the wrong IP or whatever...

anything more i can do to prevent this
Prevent you can't, but since this hit your BOGON_SPOOF chain whatever limiting the chain does (-j DROP I hope) should do.
 
Old 09-13-2006, 06:32 PM   #5
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Original Poster
Rep: Reputation: 30
Well usually worms in their DOS (?) broadcasts spoof their source address ... i have got to TARPIT them ... (P.O.M. way !)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux Spoofs (gPod) Blaa269 General 2 01-09-2004 11:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration