LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-22-2006, 01:30 AM   #1
tgo
Member
 
Registered: Dec 2004
Posts: 125

Rep: Reputation: 15
tcpdump logs question


I run a 3 nic linux gateway at home and was running tcpdump on the outside/public interface and saw a bunch of lines like these:

Code:
20:20:39.159399 IP 10.128.32.1.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length: 316
20:20:39.160390 IP 10.128.32.1.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length: 316
20:20:39.160739 IP 10.128.32.1.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length: 316
From what I can tell they are dhcp replys from a private ip over my public interface. Obviously this has some sort of malicous intent trying to pull dhcp clients onto a network.

Now to my real question... I dont see the point in this attack as even if some dhcp client had just sent a dhcp request out it wouldnt be able to contact the server as its using private ip addresses. I would see it as more of a threat is it was a public ip, but I do not see any threat from this. What if any is the point of this attack or was it just some kid scanning ranges?
 
Old 07-22-2006, 01:52 AM   #2
konsolebox
Senior Member
 
Registered: Oct 2005
Distribution: Gentoo, Slackware, LFS
Posts: 2,248
Blog Entries: 8

Rep: Reputation: 235Reputation: 235Reputation: 235
It's no longer unusual to detect even just at least 10 scans everyday. Mostly these are not hands-on scans. They're bots. Just ignore them anyway.

regards
 
Old 07-22-2006, 02:02 AM   #3
tgo
Member
 
Registered: Dec 2004
Posts: 125

Original Poster
Rep: Reputation: 15
figured they were bots was just wondering why they bother scanning with private ip addresses
 
Old 07-22-2006, 02:20 AM   #4
konsolebox
Senior Member
 
Registered: Oct 2005
Distribution: Gentoo, Slackware, LFS
Posts: 2,248
Blog Entries: 8

Rep: Reputation: 235Reputation: 235Reputation: 235
i don't know. they're not all from bad guys though. there are some companies that do these things so that they'll know some problems of the public network ahead of the intruders. for security purpose of course. and there are also some that just take a survey and post the results on a security site.
 
Old 07-23-2006, 03:31 AM   #5
tgo
Member
 
Registered: Dec 2004
Posts: 125

Original Poster
Rep: Reputation: 15
I am not worried about it I just find it sort of interesting. Anyway I put this rule it to be able to get a count and heres the results only after 2 or 3 hours. ( eth0 is public interface ).

Code:
pkts bytes target     prot opt in     out     source               destination         
2829  963K DROP       all  --  eth0   any     10.0.0.0/8           anywhere
Isps should block this at their routers so we dont have to have it fill our bandwith
 
Old 07-23-2006, 05:07 AM   #6
konsolebox
Senior Member
 
Registered: Oct 2005
Distribution: Gentoo, Slackware, LFS
Posts: 2,248
Blog Entries: 8

Rep: Reputation: 235Reputation: 235Reputation: 235
yah. it should be hard for isps but yes i agree. it's still their responsibility anyway.

but at least you feel more secure now.

so till next time
regards
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Tcpdump question? chinmays Linux - Software 9 01-08-2006 08:56 PM
tcpdump question gauge73 Linux - Newbie 2 08-09-2005 04:37 PM
tcpdump -n question Melissa22 Linux - Networking 3 03-07-2004 08:05 PM
tcpdump question Xris718 Linux - Networking 1 12-08-2003 11:42 PM
tcpdump noob question centr0 Linux - Networking 2 04-24-2003 02:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration