LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-14-2004, 02:30 AM   #1
bishal
LQ Newbie
 
Registered: Feb 2004
Location: Nepal
Posts: 25

Rep: Reputation: 15
tracking intruders


Hello all

Can anyone explain what does this line means. I have seen in syslog. I can understand somewhat only.

----------------------------------------------------------
Aug 13 22:37:28 abc-proxy kernel: IN=eth0 OUT= MAC=00:c0:26:89:5c:d8:00:30:1d:00:a3:d1:08:00 SRC=202.70.73.167 DST=xxx.xx.xx.xx LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=15 DF PROTO=TCP SPT=3013 DPT=3128 WINDOW=8760 RES=0x00 SYN URGP=62468
Aug 13 22:37:31 abc-proxy kernel: IN=eth0 OUT= MAC=00:c0:26:89:5c:d8:00:30:1d:00:a3:d1:08:00 SRC=202.70.73.167 DST=XXX.XX.XX.XX LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=22 DF PROTO=TCP SPT=3013 DPT=3128 WINDOW=8760 RES=0x00 SYN URGP=62468
--------------------------------------------------------------
 
Old 08-14-2004, 07:12 AM   #2
nukkel
Member
 
Registered: Mar 2003
Location: Belgium
Distribution: Hardened gentoo
Posts: 323

Rep: Reputation: 30
It's messages from the kernel firewall (netfilter/iptables): someone with IP 202.70.73.167 tried to connect (witness the TCP SYN flag at the end) to your TCP port 3128 (probably squid?)

Somehow you or a colleague of you ordered the firewall to log this kind of packets... You can see the firewall rules by doing "iptables -L -v" -- "man iptables" for more info, or visit www.netfilter.org

Greetings
nukkel
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
susefirewall2 and seeing intruders oily_rags SUSE / openSUSE 12 12-17-2005 12:22 AM
tracking what i said... lefty.crupps LQ Suggestions & Feedback 4 05-01-2005 01:45 AM
Website Tracking kemplej Linux - Software 1 04-25-2005 02:48 PM
tracking customers sopiaz57 Linux - Software 1 02-02-2004 01:09 PM
Microsoft’s network is hacked - Intruders believed to have stolen code for software jeremy General 3 11-26-2000 08:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration