LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-20-2005, 01:06 AM   #1
carboncopy
Senior Member
 
Registered: Jan 2003
Location: Malaysia
Posts: 1,210
Blog Entries: 4

Rep: Reputation: 45
Help analyse syslog entry


I found 7 entry as stated below in my syslog over the period of 12 hours. What is it and is it a security threat?

Code:
Dec DD HH:MM:SS carboncopy kernel: IN=ppp0 OUT=ppp0 SRC=62.34.109.XXX DST=62.34.109.XXX LEN=56 TOS=0x00 PREC=0x00 TTL=45 ID=17060 PROTO=ICMP TYPE=3 CODE=3 [SRC=62.34.109.XXX DST=2XX.XXX.XXX.XXX LEN=330 TOS=0x00 PREC=0x00 TTL=52 ID=61829 PROTO=UDP SPT=15121 DPT=6882 LEN=310 ]
Note, all 7 entry where from the same source IP.
 
Old 12-20-2005, 02:10 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by carboncopy
Code:
Dec DD HH:MM:SS carboncopy kernel: IN=ppp0 OUT=ppp0 SRC=62.34.109.XXX DST=62.34.109.XXX LEN=56 TOS=0x00 PREC=0x00 TTL=45 ID=17060 PROTO=ICMP TYPE=3 CODE=3 [SRC=62.34.109.XXX DST=2XX.XXX.XXX.XXX LEN=330 TOS=0x00 PREC=0x00 TTL=52 ID=61829 PROTO=UDP SPT=15121 DPT=6882 LEN=310 ]
just my :

Quote:
While most people associate the Internet Control Message Protocol (ICMP) with 'ping', ICMP is a key piece of the internet. ICMP is used to report problems back to the sender of a packet; this is what is happening here. Unfortunately, where NAT is involved (including SNAT, DNAT and Masquerade), there are a lot of broken implementations. That is what you are seeing with these messages.
http://www.system-linux.net/doc/shor.../FAQ.htm#faq21

also, to read more about icmp type 3 check this:
http://www.networksorcery.com/enp/pr.../icmp/msg3.htm

Last edited by win32sux; 12-20-2005 at 02:20 AM.
 
Old 12-20-2005, 02:18 AM   #3
carboncopy
Senior Member
 
Registered: Jan 2003
Location: Malaysia
Posts: 1,210

Original Poster
Blog Entries: 4

Rep: Reputation: 45
Thanks.

Note to myself, use google.
 
Old 12-20-2005, 02:25 AM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
you're welcome, hehe...

FYI, here's the google searches i used to find your answer:

http://www.google.com/search?&q=icmp+type+3

http://www.google.com/linux?&q=syslo...ype+3+brackets
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Odd entry in syslog merana Linux - Security 2 04-27-2005 06:23 AM
Syslog, where is this entry coming from? exim? boyd98 Debian 1 04-05-2005 01:46 PM
logfile analyse saavik Linux - Networking 4 03-30-2005 05:14 AM
Events on Log analyse dough29 Programming 2 11-07-2004 01:20 PM
Can anyone analyse this message? Fraxis Linux - Software 6 01-02-2002 06:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration