LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-05-2009, 01:13 PM   #1
elvisious
Member
 
Registered: Sep 2003
Distribution: Debian 5.0
Posts: 45

Rep: Reputation: 15
Question Logwatch - Logged 298 packets on interface eth0


Hi,

This is in my logwatch now and then:

Quote:
--------------------- iptables firewall Begin ------------------------


Listed by source hosts:
Logged 298 packets on interface eth0
From 10.0.0.2 - 88 packets to udp(138)
From 10.0.1.1 - 210 packets to udp(137)

Listed by source hosts:
Logged 18 packets on interface eth1
From 0.0.0.0 - 18 packets to udp(67)

---------------------- iptables firewall End -------------------------
What does it mean?

Greetz
FrankY
 
Old 10-05-2009, 01:29 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
It means that, during the reporting period, 298 packets were sent to you (or your broadcast address) that matched LOG targets in your iptables chain(s).

The first set is MS chatter:
Code:
$ egrep ' 138\/| 137\/' /etc/services 
netbios-ns      137/tcp                         # NETBIOS Name Service
netbios-ns      137/udp
netbios-dgm     138/tcp                         # NETBIOS Datagram Service
netbios-dgm     138/udp
The second set is for dhcp clients:
Code:
$ grep ' 67\/' /etc/services 
bootps          67/tcp                          # BOOTP server
bootps          67/udp
 
Old 10-05-2009, 01:35 PM   #3
elvisious
Member
 
Registered: Sep 2003
Distribution: Debian 5.0
Posts: 45

Original Poster
Rep: Reputation: 15
Is any of it unsecure?
Do I have to worry about it?
 
Old 10-05-2009, 01:37 PM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
With the caveat that I have no idea whether your system is properly secured, there is nothing unusual about the report snippet you posted. Lots of networks have similar chatter.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ERROR: The interface does not exist (UBUNTU) interface eth0 not configured anshulbhatt Linux - Networking 2 11-20-2008 12:23 PM
Logwatch full with httpd "unidentified 'other' records logged" joelunch Linux - Software 1 04-11-2007 07:39 PM
LogWatch logged error in xmdms Linux - Networking 0 12-02-2004 08:52 AM
logwatch: A total of 3 unidentified 'other' records logged rioguia Linux - Security 2 11-12-2004 09:12 AM
Bringing up interface eth0: determining ip information for eth0... failed ralphethomas Linux - Networking 0 01-24-2004 05:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration