LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-16-2009, 03:07 AM   #1
perfectpol7
Member
 
Registered: Feb 2009
Posts: 84

Rep: Reputation: 15
Is my squid proxy hacked


Hie

I had a proxy server running with fedora 10 and webmin installed. I have set bandwidth monitoring facility on. When i activate show traffic by host I notice one IP address which is out of my IP addresses. My ip address are 10.0.0/255 and the stranger one is 224.0.0.251. Is this means that I am hackered or where is this coming from. I am using webmin squid proxy and even the bandwidth monitor. Secondly how do I allocate bandwidth to different ip address in my LAN
 
Old 02-16-2009, 03:45 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Do you have any Macs on your network? That's probably the Rendezvous service.
 
Old 02-16-2009, 04:05 AM   #3
perfectpol7
Member
 
Registered: Feb 2009
Posts: 84

Original Poster
Rep: Reputation: 15
No I do not have macs and i tried to ping it but no respond.
 
Old 02-16-2009, 04:11 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
you wouldn't be able to p[ing it, it's a multicast address. Google says it's just multicast DNS - http://www.networksorcery.com/enp/pr.../multicast.htm so nothing to worry about
 
Old 02-16-2009, 04:14 AM   #5
repo
LQ 5k Club
 
Registered: May 2001
Location: Belgium
Distribution: Arch
Posts: 8,529

Rep: Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899
According to RFC 3171 this block of addresses (224.0.0.x) is reserved for
special purposes.

This is a multicast address
224.0.0.251 mDNS, Multicast DNS.

Take a look at
http://www.networksorcery.com/enp/pr.../multicast.htm
 
Old 02-16-2009, 04:38 AM   #6
perfectpol7
Member
 
Registered: Feb 2009
Posts: 84

Original Poster
Rep: Reputation: 15
thanks for the link guys my fears have gone now.
 
Old 02-16-2009, 05:27 AM   #7
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Yes, its probably your router doing Rendezvous/Mdns/Bonjour broadcasts so that the rest of you network can config itself with minimum intervention (it could be something else doing the same thing).

Wireshark will show you the source addr.

You could turn it off, but you'll probably break stuff.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
configure squid proxy with cc proxy as a parent proxy faisi Linux - Networking 1 08-10-2010 01:16 PM
squid proxy server configuration & distribution of internet without proxy gaurav_gupta082 Linux From Scratch 2 07-31-2010 11:25 AM
Using ISA Server as Parent Proxy and want to setup Squid as dwonstream proxy tauseef1 Red Hat 1 04-09-2008 01:03 AM
configure squid proxy with microsoft proxy as a parent proxy nintykola Linux - Software 1 08-28-2007 01:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration