LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-05-2009, 02:01 AM   #1
Pedroski
Senior Member
 
Registered: Jan 2002
Location: Nanjing, China
Distribution: Ubuntu 20.04
Posts: 2,116

Rep: Reputation: 73

Hi, just a question.

I installed Firestarter on Ubuntu. It says under Events:

Inbound Total 0 Serious 149, and it just keeps going up.

Serious? How?

Here is a small section of the log Events blocked. Most seem to be China Telecom ( I'm in China ). Surely even the Chinese government can't be interested in me. Hacking Embassies, ok, but my little self?

Do you think I should alter my firewall at all? Assuming I knew how!

Time:Apr 5 13:58:31 Direction: Unknown Inpp0 Out: Port:5670 Source:116.233.18.4 Destination:58.212.224.202 Length:52 TOS:0x00 Protocol:TCP Service:Unknown
Time:Apr 5 13:58:31 Direction: Unknown Inpp0 Out: Port:15000 Source:121.204.48.230 Destination:58.212.224.202 Length:57 TOS:0x00 Protocol:UDP Service:Unknown
Time:Apr 5 13:58:31 Direction: Unknown Inpp0 Out: Port:80 Source:124.116.239.2 Destination:58.212.224.202 Length:48 TOS:0x00 Protocol:TCP Service:HTTP

Who put those smileys in there? Wasn't me!
I just copied and pasted from the log text file! Nasty!

Last edited by unSpawn; 04-05-2009 at 04:26 AM. Reason: //moderator.note: please edit post, not reply yourself unless with solution.
 
Old 04-05-2009, 09:50 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
To determine what constitutes "serious", you'd need to check the Firestarter documentation, as it's a subjective term. That said, having your IP get probed for open ports and the like is quite normal and expected. Maybe run a port scanner on yourself to see what your IP looks like to the bad guys (and to verify that your firewall is sane). Basically, if your firewall is reporting those packets as having been blocked, you're good to go since they never made it into your applications. Generally speaking, it's the ones which your firewall doesn't block that you need to worry about.

NOTE: There is an option to disable smilies when you post.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firestarter??? SBN Linux - Software 2 09-30-2006 03:31 AM
Help with Firestarter rsiby Linux - Security 1 03-27-2006 09:49 AM
Firestarter hansmast Linux - Security 1 02-18-2006 02:42 PM
FIreStarter webwolf70 Linux - Security 2 06-01-2005 02:05 PM
Firestarter FW hath Linux - Security 3 02-05-2002 08:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration