LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-29-2012, 12:45 AM   #1
leslie_jones
Member
 
Registered: Sep 2011
Posts: 130

Rep: Reputation: Disabled
OT: Facebook weirdness with iptables


Recently I've started to see numerous entries where Facebook has been blocked attempting to connect in;

Code:
From 66.220.145.39 - 39 packets to tcp(49239,49240,49339,49344,49398,49399,49490,49493,49521,49540,49558,49566,49587,49590,49612,55723)
Source port is always 80 and whilst the client concerned is a Facebook user, it seems odd that contrack would drop these if they really were related/established to the active session.

It's not the first load of Facebook weirdness I've seen either. A while ago our DNS servers were regularly being bombed by Facebook effectively firing off about 20 attempts in for every one out - again caught and dropped by iptables.

In the later DNS case I'm guessing some kind of naughtiness relating to geolocation, but I can't figure out what they are trying to do with the port 80 reverse connections? I doubt that a packet capture would help much, unless I whitelist Facebook IP's, and I don't really want to do that as I can't say they are a company I would trust.

EDIT
It's just crossed my mind that it could be dodgy load balancing with direct server return.

Last edited by leslie_jones; 02-29-2012 at 12:46 AM.
 
Old 02-29-2012, 03:18 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Well it certainly looks like return traffic of some form, so you're thoughts about load balancing sound like a very good direction to explore. Some form of asymmetry somewhere local is usually a good bet for this.

Personally I would be looking at a capture, and trying to find the opening of the connection, maybe through a different interface / device. But then I try to solve *EVERYTHING* with a packet capture.w Routing issue? Packet capture. Car won't start? Packet capture. Greek financial crisis? Packet capture.

Last edited by acid_kewpie; 02-29-2012 at 03:20 AM.
 
Old 02-29-2012, 03:28 AM   #3
leslie_jones
Member
 
Registered: Sep 2011
Posts: 130

Original Poster
Rep: Reputation: Disabled
That's why it's all Greek to me ;->

Packet Capture it is then.....

Thanks Chris.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] IPTables NAT weirdness codevyper Linux - Security 4 10-09-2010 03:48 PM
iptables v1.2.9: Unknown arg `/sbin/iptables' Try `iptables -h' or 'iptables --help' Niceman2005 Linux - Security 4 12-29-2005 08:20 PM
Iptables Weirdness... paleogryph Linux - Security 2 06-25-2005 06:15 PM
Iptables DNAT weirdness matta Linux - Networking 3 04-07-2004 03:11 AM
iptables weirdness Misteree Linux - Security 8 05-27-2003 04:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration